← Back

Ingress Nginx

ingress-nginx

Vendor: Kubernetes • 10 CVEs

CVEs (10)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kubernetes
2Ingress Nginx
Nginx Ingress Controller
Jun 17, 2026
Mar 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx co...Show more
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)Show less
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Mar 9, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the...Show more
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)Show less
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Ingress nginx annotation injection causes arbitrary command execution.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Oct 25, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
May 24, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress o...Show more
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.Show less
1Kubernetes
1Ingress Nginx
Jun 17, 2026
May 6, 2022
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the...Show more
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.Show less
1Kubernetes
1Ingress Nginx
Jun 17, 2026
May 6, 2022
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API gr...Show more
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.Show less
2Kubernetes
Netapp
2Ingress Nginx
Trident
Jun 17, 2026
Oct 29, 2021
N/A· v4
7.1 HIGH· v3
5.5 MEDIUM· v2
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
1Kubernetes
1Ingress Nginx
Jun 17, 2026
Jul 29, 2020
N/A· v4
5.9 MEDIUM· v3
4.9 MEDIUM· v2
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx...Show more
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.Show less