← Back

Nginx Ingress Controller

nginx_ingress_controller

Vendor: Kubernetes • 2 CVEs

CVEs (2)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Kubernetes
2Ingress Nginx
Nginx Ingress Controller
Jun 17, 2026
Mar 19, 2026
N/A· v4
8.8 HIGH· v3
N/A· v2
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx co...Show more
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)Show less
1Kubernetes
1Nginx Ingress Controller
Nov 21, 2024
Jan 14, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.