For more information regarding the security incident at F5, the actions we are taking to address it, and our ongoing efforts to protect our customers, click here.

Forum Discussion

misterpaul's avatar
misterpaul
Icon for Nimbostratus rankNimbostratus
Mar 25, 2025

nginx-ingress and CVE-2025-1974 (aka IngressNightmare)

Yesterday a set of 5 critical vulnerability was announced in ingress-nginx which allows remote code exec and reading secrets for unauthenticated users. The discoverers have named this #IngressNightmare.

As I understand it, F5's nginx-ingress uses the same codebase.

Can F5 confirm whether nginx-ingress is or is not vulnerable to these vulnerabilities?

Thanks!  MisterPaul

References: