PoC Archive PoC Archive

tag

Kubernetes

IngressNightmare: Kubernetes ingress-nginx Admission Controller Shared-Library Injection RCE (CVE-2025-1974) EPSS 100%
CVE-2025-1974 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-07-06OS Command Injection in KubeAI via Model URL (CVE-2026-34940)
CVE-2026-34940 cloud Patched
CVE-2026-34940cloudHIGH 8.7Patched2026-07-05Kubernetes `runAsNonRoot` Bypass via UID Integer Overflow (CVE-2026-46680)
CVE-2026-46680 cloud Patched
CVE-2026-46680cloudHIGHPatched2026-07-05Apache Flink Kubernetes Operator SSRF via jarURI (CVE-2026-40564)
CVE-2026-40564 cloud Patched
CVE-2026-40564cloudHIGHPatched2026-07-05IngressNightmare - Kubernetes Ingress-NGINX Unauthenticated RCE EPSS 100%
CVE-2025-1974 (primary); also CVE-2025-1097, CVE-2025-1098, CVE-2025-24514 cloud Unverified
CVE-2025-1974cloudCRITICAL 9.8Unverified2026-05-17