PT-2025-12715 · Kubernetes+1 · Ingress-Nginx+2

Nir Ohfeld

+2

·

Published

2025-03-23

·

Updated

2026-05-16

·

CVE-2025-1974

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions
Ingress-nginx versions prior to 1.12.1, from 1.12.0-beta.0 before 1.12.1
Description
Ingress-nginx is vulnerable to a critical remote code execution (RCE) vulnerability (CVE-2025-1974) with a CVSS score of 9.8. This flaw allows unauthenticated attackers with access to the pod network to execute arbitrary code within the ingress-nginx controller. Successful exploitation could lead to full cluster takeover and exposure of sensitive secrets. The vulnerability stems from improper isolation or compartmentalization within the controller. A proof-of-concept (PoC) exploit is publicly available. This vulnerability is actively being exploited. The Admission Controller, listening on port 8443, is a key component affected by this issue.
Recommendations
Upgrade Ingress-nginx to version 1.12.1 or later. Restrict network access to the Admission Controller, specifically port 8443. Implement network segmentation, strong authentication, and authorization policies for services on port 8443. Regularly audit and patch vulnerabilities. Remove any server-snippet annotations from your ingress configurations.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-03219
BDU:2025-03220
BIT-NGINX-INGRESS-CONTROLLER-2025-1974
CVE-2025-1974
GHSA-MGVX-RPFC-9MPV
GO-2025-3567
KUBERNETESINGRESSNGINX_CVE2025_1974
OPENSUSE-SU-2025:14937-1
OPENSUSE-SU-2025:14941-1
OPENSUSE-SU-2025:14942-1
OPENSUSE-SU-2025:14943-1
OPENSUSE-SU-2025:14944-1
OPENSUSE-SU-2025:15083-1
OPENSUSE-SU-2025:15569-1
OPENSUSE-SU-2026:10050-1
OPENSUSE-SU-2026:10799-1

Affected Products

Kubernetes
Red Os
Ingress-Nginx