🔥 24×7 Proxy Interview Support · Job Support · Profile Engineering | USA • Canada • UK • Europe • Australia

Postmortem · CVE-2025-1974 · CVSS 9.8

IngressNightmare (CVE-2025-1974) — ingress-nginx Admission-Webhook RCE Postmortem

An unauthenticated request to the ingress admission webhook could run code in the controller and read every secret in the cluster. Here is the record and the fix.

Most AI platforms expose inference and agents through ingress-nginx. IngressNightmare meant anyone who could reach the admission webhook — often in-cluster, sometimes wider — could take the cluster over.

IngressNightmare (CVE-2025-1974) was a critical flaw in the Kubernetes ingress-nginx controller’s admission webhook. An attacker who could send requests to the webhook could supply a crafted Ingress object with malicious NGINX configuration directives that were injected and executed, achieving remote code execution in the controller Pod — without authentication. Because the ingress controller is highly privileged, exploitation enabled reading Secrets across all namespaces and could lead to full cluster takeover (CVSS 9.8). For AI clusters this is acute: the ingress controller often fronts every model endpoint and agent, and holds the keys to the kingdom. The record and fix are below.

What We Offer

Expert Support for Every IT Challenge

From daily job support to emergency production fixes, proxy interview guidance, and interview coaching — we have the expert for your specific need.

Real-Time Kubernetes AI Job Support

Live expert help during your working hours — running LLM inference (vLLM, KServe, Dynamo), agent runtimes and sandboxes, GPU scheduling, autoscaling, RAG pipelines, and daily platform deliverables on your real cluster so you always hit your deadlines.

Production AI Incident Support

On-call firefighting for live incidents — GPU Pods stuck Pending, CUDA/OOMKilled crashes, vLLM out-of-memory, high TTFT, model-loading failures, autoscaling that will not scale, agent loops, MCP authorization errors, and RAG/vector-DB latency — with an engineer on the call.

Interview & Candidate Marketing

Kubernetes AI proxy interview assistance, profile positioning, and candidate marketing for Platform Engineer, AI Infrastructure Engineer, GPU Infrastructure Engineer, MLOps/LLMOps, and SRE roles — real-time interview guidance, recruiter readiness, and profile visibility.

Real Situations

Incident Record

These are the real-world situations our experts resolve every day — for job support and interview assistance.

DATE: Disclosed 24 March 2025 by Wiz Research.
PLATFORM: Any Kubernetes cluster running the ingress-nginx controller (hyperscaler or on-prem).
COMPONENT: ingress-nginx controller: versions prior to v1.11.0, v1.11.0–1.11.4, and v1.12.0.
WHAT HAPPENED: Unauthenticated requests to the admission webhook allowed injection of malicious NGINX directives via a crafted Ingress object, yielding RCE in the controller Pod.
IMPACT: Remote code execution in a highly privileged controller, read access to Secrets in all namespaces, and potential full cluster takeover (CVSS 9.8, Critical).
ROOT CAUSE: The admission webhook processed attacker-controlled configuration without authentication, and NGINX config injection was possible during validation.
MITIGATION: If you cannot upgrade immediately, apply a NetworkPolicy so only the Kubernetes API server can reach the admission webhook, and consider temporarily disabling the admission webhook component.
FIX: Upgrade ingress-nginx to v1.12.1 (or later) or v1.11.5 (or later).
OPERATIONAL LESSON: Admission webhooks are code-execution surfaces. Lock their network exposure to the API server only, and keep cluster-wide controllers patched aggressively — they are single points of total compromise.

Global Reach

Real-time Kubernetes AI infrastructure support for engineers across USA, Canada, UK, Ireland, Germany, Netherlands, Switzerland, Australia, New Zealand, Singapore, UAE, and worldwide.

Available across US, Canada, UK, European, Australian, and Asia-Pacific business hours — and 24/7 for production incidents.

In-house experts — no sub-contracting or outsourcing
24/7 availability for urgent job support and interview needs
Confidential & professional — NDA available on request
Same-day onboarding for most job support and interview cases
Combined job support + proxy interview service available

Ready to Get Expert Help? Talk to Us Now.

Join 1000+ developers who resolved their job challenges and cleared interviews with real-time expert support.

Expert Help Available

Need real-time IT job support or interview help? Our experts are available 24/7 — USA, Canada, UK, Europe & worldwide.

Get Instant HelpCall Now

FAQ

Frequently Asked Questions

Everything you need to know before getting started with job support or interview assistance.

Ask on WhatsApp

Unauthenticated requests to the admission webhook allowed injection of malicious NGINX directives via a crafted Ingress object, yielding RCE in the controller Pod. Remote code execution in a highly privileged controller, read access to Secrets in all namespaces, and potential full cluster takeover (CVSS 9.8, Critical). You are likely affected if you run ingress-nginx controller: versions prior to v1.11.0, v1.11.0–1.11.4, and v1.12.0. at the versions noted in the record below. We can audit your cluster against this and the wider class of AI-infrastructure risks and tell you precisely where you are exposed.

Fix: Upgrade ingress-nginx to v1.12.1 (or later) or v1.11.5 (or later). Mitigation if you cannot patch immediately: If you cannot upgrade immediately, apply a NetworkPolicy so only the Kubernetes API server can reach the admission webhook, and consider temporarily disabling the admission webhook component. We help you apply the fix safely in production — staged rollout, verification, and the admission/network guardrails that reduce blast radius for the next issue of this class.

Admission webhooks are code-execution surfaces. Lock their network exposure to the API server only, and keep cluster-wide controllers patched aggressively — they are single points of total compromise. This is why we treat the AI-infrastructure supply chain, container runtime, and admission path as security-critical — not just the application layer.

Yes. We run a focused review of your container runtime (NVIDIA Container Toolkit / GPU Operator versions), ingress and admission webhooks, model and image supply chain, agent/tool sandboxing, and RBAC/network policy — mapping each finding to a concrete fix and a guardrail. See our Kubernetes AI security hub.

Both. This page documents a real, publicly disclosed incident with its official source so you can act on it. If you would rather an engineer work it with you — patching safely in production, or auditing for the wider class of risk — that service is available same-day and confidentially.

Official Source

Wiz Research disclosure of IngressNightmare (CVE-2025-1974 and the related CVEs) and the Kubernetes ingress-nginx security advisory. Verify affected and fixed versions against the advisory before upgrading.

Read the Wiz Research disclosure (IngressNightmare)

Get Started Today

Exposed to IngressNightmare (CVE-2025-1974) or Want a Cluster Security Review?

In-house Kubernetes, GPU, and AI-infrastructure security engineers available same-day — safe production patching, blast-radius review, and hardening against this class of risk. Talk to ProxyTechSupport on WhatsApp now.

Proxy Tech Support provides interview preparation, technical guidance, and job support services. All services are advisory and educational in nature.