Pentera
New Injection Vectors in Kubernetes Ingress-NGINX
Pages
18
Time to read
18 mins
Publication
Language
English
Pages
18
Time to read
18 mins
Publication
Language
English
This technical report discusses the findings of Pentera Labs regarding new injection vectors in Kubernetes Ingress-NGINX, building upon prior research known as IngressNightmare. The report outlines the vulnerabilities identified, including CVE-2025-1974, CVE-2025-1097, CVE-2025-1098, and CVE-2025-24514, which can lead to significant security risks such as remote code execution within Kubernetes clusters. The authors detail their methodology for replicating these vulnerabilities in a lab environment and highlight additional injection points discovered during their research. The report emphasizes the importance of timely patching and the challenges associated with exploiting these vulnerabilities in real-world scenarios. It also provides technical guidance on how to detect whether a Kubernetes cluster is affected by these vulnerabilities, including specific commands and configurations necessary for testing. The report serves as a critical resource for those managing Kubernetes environments, aiming to enhance security awareness and remediation strategies.