CVE-2025-1974: ingress-nginx admission controller RCE escalation
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Other sources
Ingress Controllers play a critical role within Kubernetes clusters by enabling the functionality of Ingress resources. Azure Kubernetes Service (AKS) is aware of several security vulnerabilities affecting the Kubernetes ingress-nginx controller, including CVE-2025-1098, CVE-2025-1974, CVE-2025-1097, CVE-2025-24514, and CVE-2025-24513. Customers running this controller on their AKS clusters are advised to update to the latest patched versions (v1.11.5 and v1.12.1) to mitigate potential risks.
— Microsoft
Kubernetes: Vulnerability in Kubernetes NGINX Ingress Controller
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-1974?
CVE-2025-1974 has been classified with a high severity indicating potential remote code execution risks.
What are the potential impacts of CVE-2025-1974?
CVE-2025-1974 could allow attackers to execute arbitrary code within Kubernetes clusters, compromising security.
How do I fix CVE-2025-1974?
To mitigate CVE-2025-1974, it is recommended to upgrade to the latest version of the ingress-nginx controller that addresses this vulnerability.
Which software is affected by CVE-2025-1974?
CVE-2025-1974 specifically affects the Azure Kubernetes Service using the ingress-nginx controller.
When was CVE-2025-1974 disclosed?
CVE-2025-1974 was disclosed in March 2025 as part of ongoing security assessments for Kubernetes.