Critical IngressNightmare Vulnerabilities Found in Kubernetes Environments

Critical vulnerabilities, collectively termed "IngressNightmare," have been identified in the Ingress NGINX Controller of Kubernetes environments, potentially impacting over 40% of internet-facing clusters. These flaws allow remote, unauthenticated attackers to execute arbitrary commands, potentially taking full control of affected Kubernetes clusters. 

The vulnerabilities include CVE-2025-24514, CVE-2025-1097, and CVE-2025-1098, which enable attackers to inject custom NGINX configuration directives, such as routing rules and security settings. To achieve remote code execution, these flaws can be combined with CVE-2025-1974. This combination of vulnerabilities has been assigned a CVSS severity score of 9.8, highlighting its critical nature. 

Organizations utilizing Kubernetes with Ingress NGINX Controller are strongly advised to apply the patches released by Kubernetes maintainers promptly to mitigate these risks and protect their environments from potential exploitation. 

https://www.darkreading.com/application-security/critical-ingressnightmare-vulns-kubernetes-environments

Comments

Popular posts from this blog

Secure Vibe Coding Guide: Best Practices for Writing Secure Code

OWASP SAMM Skills Framework Enhances Software Security Roles

Opengrep: Open-Source SAST for Code Security and Innovation