← Back to Resources
Open Source NewsMarch 24, 20252 min read

"IngressNightmare" Critical RCE Vulnerabilities Disclosed in Ingress-NGINX

By BIOS Founding Team

"IngressNightmare" Critical RCE Vulnerabilities Disclosed in Ingress-NGINX

Wiz Research disclosed a set of critical vulnerabilities, including the headline CVE-2025-1974 (CVSS 9.8), in the widely used Kubernetes Ingress-NGINX Controller.

Collectively dubbed 'IngressNightmare,' the flaws allowed unauthenticated remote code execution in the ingress controller pod, potentially leading to full cluster compromise, prompting urgent patching guidance across the ecosystem.

Full details: https://projectdiscovery.io/blog/ingressnightmare-unauth-rce-in-ingress-nginx