Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2025-1974 PoC — ingress-nginx admission controller RCE escalation

Source
Associated Vulnerability
Title: ingress-nginx admission controller RCE escalation (CVE-2025-1974)
Description:A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Description
PoC for CVE-2025-1974: Critical RCE in Ingress-NGINX (<v1.12.1) via unsafe config injection. Exploitable from the pod network without credentials, enabling code execution and potential cluster takeover. Fixed in v1.12.1 and v1.11.5. For research/education only.
Readme
⚠️ Critical RCE in Ingress-NGINX via Configuration Injection (**CVE-2025-1974** and more)<br><br>This repository contains a proof-of-concept (PoC) exploit for **CVE-2025-1974**, a Critical (**CVSS 9.8**) vulnerability in the Ingress-NGINX controller for Kubernetes. This flaw allows unauthenticated remote code execution via unsafe configuration injection when using the Validating Admission Controller. It is the most serious of a set of five vulnerabilities disclosed and patched on March 26, 2025.<br><br>📌 Impact:<br>• Affected Versions: Ingress-NGINX controller prior to v1.12.1 / v1.11.5<br>• Attack Surface:<br> • Exploitable by any workload on the Pod network — no credentials or admin privileges required<br> • Attackers can inject arbitrary NGINX directives (e.g., content_by_lua_block) via annotations like configuration-snippet<br> • When combined with misconfigurations, attackers can exfiltrate Secrets or achieve full cluster compromise<br>• Scope:<br> • Ingress-NGINX often has access to all cluster Secrets by default<br> • Pods in a typical cloud VPC or corporate network can reach the admission controller endpoint<br> • Affected clusters include those running Ingress-NGINX with admission control enabled (default in many setups)<br><br>🛡️ Mitigation:<br>• Upgrade to Ingress-NGINX v1.12.1 or v1.11.5<br>• Disable risky annotations (configuration-snippet, server-snippet, etc.)<br>• Lock down network access to the Validating Admission Webhook<br>• Apply strict RBAC to prevent unauthorized Ingress creation<br><br>🧪 This PoC demonstrates how attackers can leverage the vulnerability to run arbitrary code inside the ingress controller pod — which often has access to internal services and secrets — escalating to full cluster takeover in vulnerable configurations.<br><br>🚨 Disclaimer: This PoC is for educational and research purposes only. Do not use it without explicit permission.
File Snapshot

Log in to view the POC file snapshot cached by Shenlong Bot

Log in to view
Remarks
    1. It is advised to access via the original source first.
    2. Local POC snapshots are reserved for subscribers — if the original source is unavailable, the local mirror is part of the paid plan.
    3. Mirroring, verifying, and maintaining this POC archive takes ongoing effort, so local snapshots are a paid feature. Your subscription keeps the archive online — thank you for the support. View subscription plans →