Remote Code Execution Vulnerabilities in Ingress NGINX | Wiz Blog

Keypoints :

  • Discovery of CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974 vulnerabilities.
  • These vulnerabilities allow unauthorized access to secret data and potential cluster takeover.
  • Approximately 43% of cloud environments are vulnerable, impacting many public-facing Kubernetes clusters.
  • Ingress NGINX Controller is widely used and is crucial for routing external traffic to Kubernetes services.
  • Vulnerabilities arise from the admission controller’s accessibility and the configuration validation process.
  • Patching is advised with specific recommended versions to mitigate risks.
  • Research findings are shared to strengthen overall cloud security practices.

Full Story: https://www.wiz.io/blog/ingress-nginx-kubernetes-vulnerabilities