Postmortem · CVE-2025-1974 · CVSS 9.8
An unauthenticated request to the ingress admission webhook could run code in the controller and read every secret in the cluster. Here is the record and the fix.
Most AI platforms expose inference and agents through ingress-nginx. IngressNightmare meant anyone who could reach the admission webhook — often in-cluster, sometimes wider — could take the cluster over.
IngressNightmare (CVE-2025-1974) was a critical flaw in the Kubernetes ingress-nginx controller’s admission webhook. An attacker who could send requests to the webhook could supply a crafted Ingress object with malicious NGINX configuration directives that were injected and executed, achieving remote code execution in the controller Pod — without authentication. Because the ingress controller is highly privileged, exploitation enabled reading Secrets across all namespaces and could lead to full cluster takeover (CVSS 9.8). For AI clusters this is acute: the ingress controller often fronts every model endpoint and agent, and holds the keys to the kingdom. The record and fix are below.
What We Offer
From daily job support to emergency production fixes, proxy interview guidance, and interview coaching — we have the expert for your specific need.
Live expert help during your working hours — running LLM inference (vLLM, KServe, Dynamo), agent runtimes and sandboxes, GPU scheduling, autoscaling, RAG pipelines, and daily platform deliverables on your real cluster so you always hit your deadlines.
On-call firefighting for live incidents — GPU Pods stuck Pending, CUDA/OOMKilled crashes, vLLM out-of-memory, high TTFT, model-loading failures, autoscaling that will not scale, agent loops, MCP authorization errors, and RAG/vector-DB latency — with an engineer on the call.
Kubernetes AI proxy interview assistance, profile positioning, and candidate marketing for Platform Engineer, AI Infrastructure Engineer, GPU Infrastructure Engineer, MLOps/LLMOps, and SRE roles — real-time interview guidance, recruiter readiness, and profile visibility.
Real Situations
These are the real-world situations our experts resolve every day — for job support and interview assistance.
Global Reach
Real-time Kubernetes AI infrastructure support for engineers across USA, Canada, UK, Ireland, Germany, Netherlands, Switzerland, Australia, New Zealand, Singapore, UAE, and worldwide.
Available across US, Canada, UK, European, Australian, and Asia-Pacific business hours — and 24/7 for production incidents.
Join 1000+ developers who resolved their job challenges and cleared interviews with real-time expert support.
Expert Help Available
Need real-time IT job support or interview help? Our experts are available 24/7 — USA, Canada, UK, Europe & worldwide.
FAQ
Everything you need to know before getting started with job support or interview assistance.
Ask on WhatsAppWiz Research disclosure of IngressNightmare (CVE-2025-1974 and the related CVEs) and the Kubernetes ingress-nginx security advisory. Verify affected and fixed versions against the advisory before upgrading.
Read the Wiz Research disclosure (IngressNightmare)Get Started Today
In-house Kubernetes, GPU, and AI-infrastructure security engineers available same-day — safe production patching, blast-radius review, and hardening against this class of risk. Talk to ProxyTechSupport on WhatsApp now.
Proxy Tech Support provides interview preparation, technical guidance, and job support services. All services are advisory and educational in nature.