CVE-2025-1974
Description
ingress-nginx admission controller RCE escalation
In plain language
AI Act nowCVE-2025-1974 is a serious remote code execution bug in the ingress-nginx admission controller, and a typical small business running Kubernetes should treat it as an urgent patch if your cluster exposes ingress-nginx to the network.
Unauthenticated remote code execution can be triggered over the network in the ingress-nginx admission controller (CWE-653), potentially escalating to full compromise of the ingress-nginx system.
What to do now
- Check the ingress-nginx version running in your cluster (the controller image/chart) and confirm whether it is older than 1.11.5 or 1.12.1.
- Check whether the Validating Admission Controller functionality of ingress-nginx is enabled.
- If you are on an affected version, upgrade ingress-nginx to the fixed release: 1.11.5 (or 1.12.1 if that is your supported track).
- If you cannot upgrade immediately, temporarily mitigate by disabling the Validating Admission Controller functionality of ingress-nginx until the upgrade is complete.
- After upgrading, verify the controller pods restart cleanly and that the Validating Admission Controller setting matches your intended security posture.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
- Киберугрозы 2025-2026: какие уязвимости были и будут в трендеru·Positive Technologies (Хабр)· Roundup rce
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-1974 and every CVE in our database. Create a free account — no credit card required.
Create Free Account