← back
CVE-2025-1974criticalCWE-653

ingress-nginx admission controller RCE escalation

87Vexday Risk Score

Patch soon. It has a working public exploit.

ssvc Attendcvss 9.8epss 100%
from disclosure to weapon0 days
Published on NVDMar 24
1st PoCMar 24
exploitation probability
100%top 1% of all CVEs
observed exploitation
nono source reports it
27 public exploit(s)
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.