PoC Archive PoC Archive

tag

Admission-Controller

  • CVE-2025-1974 cloud CRITICAL 9.8 EPSS 100%

    IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974)

    The ingress-nginx admission controller validates incoming Ingress objects by rendering a temporary NGINX configuration and running nginx -t against it — but the validation webhook itself has no authentication and accepts attacker-controlled configuration…

    Unverified 2026-07-06
  • CVE-2025-1974 cloud CRITICAL 9.8 EPSS 100%

    IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE

    IngressNightmare is a chain of critical vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) in the Kubernetes Ingress-NGINX admission controller. Discovered by Wiz Research, the vulnerabilities allow an unauthenticated attacker…

    Unverified 2026-05-17