TGViewer
DevOps & SRE notes DevOps & SRE notes @devops_sre_notes Β· 13.3K subscribers
Post #2037 2.17K
πŸ”₯ Critical vulnarabliiity in ingress-nginx controlller

9.8/10 πŸ”₯ https://github.com/advisories/GHSA-mgvx-rpfc-9mpv

If you're running Kubernetes with the ingress-nginx controller and are affected by the vulnerability described in GHSA-mgvx-rpfc-9mpv (CVE-2025-1974), you face several serious security risks:

Critical Security Risks

This vulnerability, published on March 25, 2025, is part of a set of critical flaws collectively named "IngressNightmare" with a CVSS score of 9.8[6]. The specific issues include:

- Unauthenticated Remote Code Execution (RCE): An attacker with access to the pod network can execute arbitrary code in the context of the ingress-nginx controller without authentication[1][2].

- Cluster-wide Secret Exposure: The vulnerability allows attackers to access and steal all secrets accessible to the controller. In default installations, the controller can access all secrets across all namespaces in the cluster[1][3].

- Complete Cluster Takeover: Due to the elevated privileges of the admission controller, successful exploitation could lead to full compromise of your Kubernetes environment[3][6].

- Public Exposure Risk: Over 6,500 clusters with publicly accessible admission controllers are at immediate risk, including those operated by Fortune 500 companies[8].

How the Vulnerability Works

The attack targets the admission controller component of the ingress-nginx controller:

1. The vulnerability allows attackers to inject arbitrary NGINX configuration remotely by sending a malicious ingress object directly to the admission controller[3].

2. When the controller processes this malicious object during validation, it causes the NGINX validator to execute malicious code[6][8].

3. The admission controller's elevated privileges and network accessibility create a critical escalation path, allowing an attacker to access sensitive resources across the entire cluster[3].

Required Action

To mitigate this issue, you should:

- Update immediately to one of the patched versions: 1.12.1, 1.11.5, or 1.10.7[6].

- Ensure your admission webhook endpoint is not exposed externally[6].

- Limit access to the admission controller to only the Kubernetes API Server[6].

- Temporarily disable the admission controller component if it's not needed[6].

This vulnerability affects approximately 43% of cloud environments, making it a widespread and serious threat to Kubernetes deployments[6].
GitHub CVE-2025-1974 - GitHub Advisory Database ingress-nginx admission controller RCE escalation
  • 😱 7
  • πŸ‘ 5
  • πŸ”₯ 4
More from @devops_sre_notes
  1. Oct 6, 2026Post #2757
  2. Oct 5, 2026Post #2756
  3. Oct 3, 2026Post #2755
  4. Oct 2, 2026Post #2754
  5. Oct 1, 2026Post #2753
  6. Sep 29, 2026Post #2752
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook β†’Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 β†’