CVE-2025-1974: The IngressNightmare in Kubernetes | Wiz Blog
AI Summary
Wiz Research discovered a series of critical unauthenticated Remote Code Execution (RCE) vulnerabilities in Ingress NGINX Controller for Kubernetes, collectively dubbed IngressNightmare. These vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974) allow attackers to inject malicious NGINX configurations and achieve remote code execution on the ingress controller pod, leading to full cluster compromise. The admission controller, which is exposed without authentication by default, enables exploitation by processing untrusted admission review requests. Over 43% of cloud environments are estimated to be vulnerable, with more than 6,500 clusters already exposed to the public internet.
AI-extracted · verify before operational use