CVE-2025-1974
CRITICAL 9.8EPSS 99.5%
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 99.52% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-653
- Published
- 2025-03-24
- Updated
- 2026-02-26
Proof-of-concept exploits (26)
- 0xBingo/CVE-2025-19740★ · 2025-03-27
- Armand2002/Exploit-CVE-2025-1974-Lab0★ · 2025-07-14
- BiiTts/POC-IngressNightmare-CVE-2025-19740★ · 2025-08-10
- Esonhugh/ingressNightmare-CVE-2025-1974-exps98★ · 2025-05-06
- Rubby2001/CVE-2025-1974-go1★ · 2025-04-10
- abrewer251/CVE-2025-1974_IngressNightmare_PoC0★ · 2025-05-06
- aninfosec/IngressNightmare0★ · 2025-06-15
- chhhd/CVE-2025-19741★ · 2025-04-26
- dttuss/IngressNightmare-RCE-POC1★ · 2025-03-26
- gian2dchris/ingress-nightmare-poc0★ · 2025-10-08
- hakaioffsec/IngressNightmare-PoC250★ · 2025-03-26
- hi-unc1e/CVE-2025-1974-poc4★ · 2025-03-27
- iteride/CVE-2025-19740★ · 2025-09-23
- lufeirider/IngressNightmare-PoC9★ · 2025-03-31
- rjhaikal/POC-IngressNightmare-CVE-2025-19741★ · 2025-03-28
- salt318/CVE-2025-19740★ · 2025-04-27
- yanmarques/CVE-2025-19740★ · 2025-03-25
- yoshino-s/CVE-2025-197453★ · 2025-03-25
- zulloper/CVE-2025-19740★ · 2025-03-31
- zwxxb/CVE-2025-19748★ · 2025-04-01
- BoianEduard/CVE-2025-1974
- I3r1h0n/IngressNightterror
- gunyakit/CVE-2025-1974-PoC-exploit
- zsxen/CVE-2025-1974
- paeyz/net_kube
- seojinn0713/net_kube