k8s.io/ingress-nginx
Go17 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting k8s.io/ingress-nginxpage 1 of 1
- CVE-2018-1002104MEDIUMCVSS 5.3EG 5.3fixed in 1.52020-01-14
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
- CVE-2020-8553MEDIUMCVSS 5.9EG 5.9fixed in 0.28.02020-07-29
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes…
- CVE-2021-25745HIGHCVSS 7.6EG 7.6fixed in 1.2.02022-05-06
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the …
- CVE-2021-25748HIGHCVSS 7.6EG 7.6fixed in 1.2.12023-05-24
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `netw…
- CVE-2022-4886HIGHCVSS 8.8EG 8.8fixed in 1.8.02023-10-25
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
- CVE-2023-5043HIGHCVSS 8.8EG 8.8fixed in 1.9.02023-10-25
Ingress nginx annotation injection causes arbitrary command execution.
- CVE-2023-5044HIGHCVSS 8.8EG 8.9fixed in 1.9.02023-10-25
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
- CVE-2025-1097HIGHCVSS 8.8EG 8.8fixed in 1.11.5 or 1.12.1, by version range2025-03-25
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in th…
- CVE-2025-1098CRITICALCVSS 8.8EG 9.0fixed in 1.11.5 or 1.12.1, by version range2025-03-25
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbit…
- CVE-2025-1974CRITICALCVSS 9.8EG 9.8fixed in 1.11.5 or 1.12.1, by version range2025-03-25
A security issue was discovered in Kubernetes where under certain conditions, an unauthenticated attacker with access to the pod network can achieve arbitrary code execution in the context of the ingress-nginx controller. This can lead to …
- CVE-2025-24513MEDIUMCVSS 4.8EG 4.8fixed in 1.11.5 or 1.12.1, by version range2025-03-25
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal with…
- CVE-2025-24514HIGHCVSS 8.8EG 8.8fixed in 1.11.5 or 1.12.1, by version range2025-03-25
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context…
- CVE-2026-1580HIGHCVSS 8.8EG 8.8fixed in 1.13.7 or 1.14.3, by version range2026-02-03
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingres…
- CVE-2026-24512HIGHCVSS 8.8EG 8.8fixed in 1.13.7 or 1.14.3, by version range2026-02-03
A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and …
- CVE-2026-24513LOWCVSS 3.1EG 3.1fixed in 1.13.7 or 1.14.3, by version range2026-02-03
A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a…
- CVE-2026-24514MEDIUMCVSS 6.5EG 6.5fixed in 1.13.7 or 1.14.3, by version range2026-02-03
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory…
- CVE-2026-4342HIGHCVSS 8.8EG 8.8fixed in 0.0.0-20260319175635-5183b7d861372026-03-19
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and discl…
Check whether k8s.io/ingress-nginx is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for k8s.io/ingress-nginx CVEs against the assets you own.
Book a Demo →