CVE-2025-1974
Kubernetes · Published March 24, 2025
9.8
CVSS v3.1
CRITICALPatch availableGet patch
Description
Ingress NGINX Controller for Kubernetes allows unauthenticated remote code execution via the admission webhook. Named 'IngressNightmare' — affects ~43% of cloud environments. An attacker on the pod network can achieve cluster-level RCE.
Affected Products
- ingress-nginx < 1.11.5
- ingress-nginx < 1.12.1
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H