Input validation error in Ingress-NGINX Controller for Kubernetes - CVE-2025-1974
Published: March 24, 2025 / Updated: June 27, 2025
Vulnerability identifier: #VU105987
CSH Severity: Critical
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-1974
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to an unspecified vulnerability in admission controller. A remote non-authenticated attacker with access to the pod network and execute arbitrary code in the context of the ingress-nginx controller
Affected software
Ingress-NGINX Controller for Kubernetes
Communications Unified Assurance
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
SmartFabric Manager
Dell EMC Container Storage Modules
Communications Unified Assurance
Oracle Communications Cloud Native Core Network Function Cloud Native Environment
SmartFabric Manager
Dell EMC Container Storage Modules
How to mitigate CVE-2025-1974
Install update from vendor's website.
Ingress-NGINX Controller for Kubernetes - addressed in versions 1.11.5, 1.12.1
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0
SmartFabric Manager - update to 1.3.0
Dell EMC Container Storage Modules - update to 1.14.0
Links to Public Exploits and PoC-codes
- Exploit #11414 - exploit-cve-2025-1974 () (May 23, 2025)
- Exploit #11380 - CVE-2025-1974_IngressNightmare_PoC (May 9, 2025)
- Exploit #11306 - CVE-2025-1974-go (Exploit CVE-2025-1974 with a single file.) (April 11, 2025)
- Exploit #11261 - CVE-2025-1974 (March 31, 2025)
- Exploit #11253 - IngressNightmare-POCs (March 25, 2025)
- Exploit #11252 - CVE-2025-1974 (March 25, 2025)
External References
Related Security Bulletins
- Multiple vulnerabilities in Ingress-NGINX Controller for Kubernetes
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Network Function Cloud Native Environment
- Dell SmartFabric Manager update for third-party components
- Dell Container Storage Modules update for ingress-nginx
- Multiple vulnerabilities in Communications Unified Assurance