Current CyberSecurity Advisories

Critical vulnerabilities in Ingress-NGINX Controller for Kubernetes

Release date
26 March 2025
Alert rating
Critical

Description

The Australian Signals Directorate’s Australian Cyber Security Centre (ACSC) is aware of critical vulnerabilities affecting Ingress-NGINX Controller for Kubernetes. Customers should update to the latest patched version immediately.

Audience

Small & medium businessesOrganisations & Critical InfrastructureGovernment

Current update

This alert is relevant to Australians who use Ingress-NGINX Controller for Kubernetes.

These vulnerabilities impact versions prior to:

  • NGINX Controller version 1.12.1 and 1.11.5

This alert is intended to be understood by technical users. Customers are encouraged to patch to the latest version.

Background / What has happened?

  • Kubernetes maintainers have published an advisory detailing the following vulnerabilities in Ingress-NGINX Controller that could allow unauthenticated remote code execution and full cluster takeover:
    • CVE-2025-1097
    • CVE-2025-1098
    • CVE-2025-1974
    • CVE-2025-24513
    • CVE-2025-24514
  • Ingress-NGINX Controller enables configurable routing of external traffic to services within a Kubernetes cluster.
  • Exploitation of these vulnerabilities could allow an actor to execute arbitrary code, access all cluster secrets across namespaces, and potentially lead to complete cluster takeover.

Mitigation / How do I stay secure?

The ASD’s ACSC recommends businesses, organisations, and government entities:

  • Review the advice and monitor the guidance at the official Kubernetes maintainer’s Ingress-NGINX Github Repository Kubernetes – Ingress-NGINX Releases
  • Update to the latest version of Ingress-NGINX Controller.
  • Ensure the admission webhook endpoint is not exposed externally.

Further information and details can be found at:

Assistance / Where can I go for help?

Organisations or individuals that have been impacted or require assistance can contact us via 1300 CYBER1 (1300 292 371).

Protect your assets with Predictive

TisaAssist bot
🤖 Hello, how can I assist you today?
I can help you with:
✅ Answer questions related to the website.
✅ Help you understand things you don't know.
❓ What's Tisalabs
💻 What's IoT
🔒 Why sensor data must be protected?