Collected research
CVE-2025-1974: The IngressNightmare in Kubernetes
Ingress-NGINX's unauthenticated admission controller builds an NGINX config from a submitted Ingress object and injects annotation values unsanitised. Chained with the undocumented ssl_engine directive and a shared library smuggled into the pod through client-body buffering, this gives unauthenticated RCE and access to every cluster secret.
Record
- Researcher
- Nir Ohfeld, Ronen Shustin, Sagi Tzadik and Hillai Ben-Sasson
- Published by
- wiz.io
- Date
- Topic
- Other
In the archive
Related sources
- Admission-controller detection template
- IngressNightmare vulnerable lab
- Kubernetes disclosure
- AWS advisory
- Google Cloud advisory
Tags
This page is the archive's own catalogue record. The research is the work of Nir Ohfeld, Ronen Shustin, Sagi Tzadik and Hillai Ben-Sasson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .