A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Published: 2025-03-25
Frequently asked questions about five vulnerabilities in the Ingress NGINX Controller for Kubernetes, collectively known as IngressNightmare.
https://www.cisa.gov/news-events/ics-advisories/icsa-25-100-05
https://www.theregister.com/2025/03/25/kubernetes_flaw_rce_risk/
https://thehackernews.com/2025/03/critical-ingress-nginx-controller.html
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-1974
https://cloud.google.com/support/bulletins/index#gcp-2025-013
https://aws.amazon.com/security/security-bulletins/AWS-2025-006/
https://github.com/vbrik/distro-package-cve-query
https://github.com/shunfeng8421/exploit-library
https://github.com/diedromeo/CVE-Labs-2025-2026
https://github.com/shunfeng8421/security-audit
https://github.com/baranchen/ingress-nginx
https://github.com/ChovTheHacker/EREBUS
https://github.com/hhdeptrai/cve_tool_backup
https://github.com/EvanThomasLuke/HACK-AGI-CONTAINERS
https://github.com/ndouglas-cloudsmith/ExploitPwned
https://github.com/Su1ph3r/Cepheus
https://www.exploit-db.com/exploits/52475
https://github.com/seta-hoangbui/CVE_search
https://github.com/gunyakit/CVE-2025-1974-PoC-exploit
https://github.com/Armand2002/Exploit-CVE-2025-1974-Lab
https://github.com/B1ack4sh/Blackash-CVE-2025-1974
https://github.com/PuddinCat/GithubRepoSpider
https://github.com/salt318/CVE-2025-1974
https://github.com/chhhd/CVE-2025-1974
https://github.com/Rubby2001/CVE-2025-1974-go
https://github.com/tuladhar/ingress-nightmare
https://github.com/accuknox/CVE-PoC-Collection
https://github.com/0xBingo/CVE-2025-1974
https://github.com/hakaioffsec/IngressNightmare-PoC
https://github.com/m-q-t/ingressnightmare-detection-poc
https://github.com/zwxxb/CVE-2025-1974
https://github.com/yanmarques/CVE-2025-1974
Published: 2025-03-25
Updated: 2026-04-15
Named Vulnerability: IngressNightmare
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 9.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity: Critical
EPSS: 0.99525
Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.
Vulnerability Being Monitored