CVE-2025-1974 is a critical security vulnerability in Kubernetes ingress-nginx controllers, allowing unauthenticated attackers on the pod network to achieve arbitrary code execution. This can lead to the disclosure of sensitive Secrets, potentially cluster-wide in default installations. With a CVSS score of 9.8 (CRITICAL) and an EPSS percentile exceeding 99.5%, the vulnerability is easily exploitable over the network with low attack complexity. Exploit code is publicly available on platforms like ExploitDB and GitHub, and it has garnered significant community discussion and media coverage, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.11.4CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ingress-nginx admission controller RCE escalation
Mar 25, 2025ingress-nginx: ingress-nginx admission controller RCE escalation
Mar 24, 2025Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
Mar 11, 2025Multiple Security Issues in NGINX Ingress Controller (CVE-2025-1974)
Jan 1, 2025ingress-nginx admission controller RCE escalation
Multiple security issues in NGINX Ingress Controller (ingress-nginx)
ingress-nginx admission controller RCE escalation
ingress-nginx admission controller RCE escalation
Multiple security issues in NGINX Ingress Controller, including CVE-2025-1974
ingress-nginx admission controller RCE escalation