
A minimal test tool to help detect annotation injection vulnerabilities in Kubernetes NGINX Ingress controllers. This script sends a crafted AdmissionReview request to simulate a potential exploit path from CVE-2025-1974 and checks for signs of misinterpreted annotations in controller logs.
This script tests for annotation injection vulnerabilities in Kubernetes clusters using the NGINX Ingress Controller. It is meant for detection purposes only in relation to CVE-2025-1974, which allows malicious annotations to influence NGINX configuration.
The vulnerability, disclosed by Wiz.io (blog post), involves injecting annotations that are improperly handled by the controller. For instance:
nginx.ingress.kubernetes.io/auth-url: "http://placeholder/#; error_log /root/this_path_shouldnt_exist.log debug; #"
This can lead to unexpected NGINX configuration behavior and permission errors if processed. In more advanced scenarios, this type of injection could be chained with other misconfigurations to achieve remote code execution (RCE).
AdmissionReview payload from a YAML file./validate endpoint.admission_review.yaml: Contains the crafted AdmissionReview request.main.py: Sends the payload to the controller.First, forward the admission controller port:
kubectl port-forward -n ingress-nginx svc/ingress-nginx-controller-admission 8443:443
Then run:
python main.py --url https://localhost:8443
Check ingress controller logs:
kubectl logs -n ingress-nginx -l app.kubernetes.io/component=controller
You may see:
nginx: [emerg] open() "/root/this_path_shouldnt_exist.log" failed (13: Permission denied)
This indicates the annotation was improperly executed as a directive.
For educational and authorized testing only. Do not run on systems without permission.
Use this tool to verify whether your cluster is vulnerable to annotation injection via NGINX Ingress. Exploitation of this vulnerability may be part of a broader attack chain leading to remote code execution.