IngressNightmare: CVE-2025-1974 - 9.8 Critical Unauthenticated Remote Code Execution Vulnerabilities in Ingress NGINX
ID: 2629c38d-c11f-5cec-89ad-e99e811c7dd3
STIX ID: report--2629c38d-c11f-5cec-89ad-e99e811c7dd3
Feed Name: Wiz Blog
**IngressNightmare (Wiz Research)**: Wiz Research disclosed a critical chain of vulnerabilities in the Ingress NGINX Controller (multiple CVEs, CVSS 9.8) that allow unauthenticated injection of NGINX configuration via AdmissionReview inputs and ingresses, enabling remote code execution by loading an uploaded shared library and leading to full cluster secret access and potential cluster takeover; the report provides technical details, affected versions, mitigations (upgrade to 1.12.1/1.11.5, restrict admission webhook network access, or disable it temporarily), detection guidance, and responsible disclosure timeline, and highlights wide real-world exposure and migration/EOL guidance for ingress-nginx.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
