Web Hack List

Collected research

CVE-2025-1974: The IngressNightmare in Kubernetes

Ingress-NGINX's unauthenticated admission controller builds an NGINX config from a submitted Ingress object and injects annotation values unsanitised. Chained with the undocumented ssl_engine directive and a shared library smuggled into the pod through client-body buffering, this gives unauthenticated RCE and access to every cluster secret.

Record

Researcher
Nir Ohfeld, Ronen Shustin, Sagi Tzadik and Hillai Ben-Sasson
Published by
wiz.io
Date
Topic
Other

In the archive

Related sources

Tags

This page is the archive's own catalogue record. The research is the work of Nir Ohfeld, Ronen Shustin, Sagi Tzadik and Hillai Ben-Sasson, first published at the original source. Preserved copies are kept so the citation survives its host; this one was last captured on .