CVE-2025-1098
HIGH 8.8EPSS 83.5%
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
- CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.8 HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS
- 83.50% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- high · CWE-20
- Published
- 2025-03-24
- Updated
- 2026-02-26
Proof-of-concept exploits (6)
- Esonhugh/ingressNightmare-CVE-2025-1974-exps98★ · 2025-05-06
- gian2dchris/ingress-nightmare-poc0★ · 2025-10-08
- hakaioffsec/IngressNightmare-PoC250★ · 2025-03-26
- lufeirider/IngressNightmare-PoC9★ · 2025-03-31
- salt318/CVE-2025-19740★ · 2025-04-27
- I3r1h0n/IngressNightterror