FlawAtlas
Search the atlas
CVE-2026-4342 High

ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx

ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx

Exploit probability 1.5%
Published March 23, 2026
Required by Not available
Last source change May 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

289 explicit affected versions

Go k8s.io/ingress-nginx
Go k8s.io/ingress-nginx

03 / CONNECTIONS

Connected vulnerabilities

related OPENSUSE-SU-2026:21483-1

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2026-4342

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

View original source
Open Source Vulnerabilities GO-2026-4796

ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx

View original source
Open Source Vulnerabilities GHSA-f53h-mxv9-cp98

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

View original source

05 / REFERENCES

Further evidence