CVE-2025-1098
ingress-nginx controller - configuration injection via unsanitized mirror annotations
- Published
- Mar 24, 2025
- Updated
- Feb 26, 2026
- Assigning CNA
- kubernetes
- Evidence observed
- Feb 4, 2026
ingress-nginx controller - configuration injection via unsanitized mirror annotations
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
This is a PoC code to exploit the IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, and CVE-2025-1974).
IngressNightmare POC. world first non-blind remote execution exploitation with multi-advanced exploitation methods. allow on disk exploitation. CVE-2025-24514 - auth-url injection, CVE-2025-1097 - auth-tls-match-cn injection, CVE-2025-1098 – mirror UID injection -- all available.
One-click proof-of-concept exploit script for IngressNightmare vulnerabilities (CVE-2025-1097, CVE-2025-1098, CVE-2025-24514, CVE-2025-1974) targeting Kubernetes ingress controllers.
My view on IngressNightmare vulnerability (CVE-2025-1974)
CVE-2025-1974
Poc for Ingress RCE
Beatriz Fresno Naumova · multiple · Feb 4, 2026
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.