ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
02 / AFFECTED SOFTWARE
Affected packages
289 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
05 / REFERENCES
Further evidence
- http://www.openwall.com/lists/oss-security/2026/03/19/9
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/4xxx/CVE-2026-4342.json
- https://github.com/kubernetes/ingress-nginx
- https://github.com/kubernetes/kubernetes/issues/137893
- https://nvd.nist.gov/vuln/detail/CVE-2026-4342
- https://github.com/advisories/GHSA-f53h-mxv9-cp98
- https://github.com/kubernetes/ingress-nginx/commit/5183b7d861377a9a2f6d2acaf44f8f6abd5cd0aa