CVE-2026-24514: ingress-nginx Admission Controller denial of service
A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24514?
CVE-2026-24514 is classified as a denial of service vulnerability that can significantly impact the ingress-nginx Admission Controller.
How do I fix CVE-2026-24514?
To mitigate CVE-2026-24514, you should limit the size of requests that the validating admission controller processes.
What causes CVE-2026-24514?
CVE-2026-24514 is caused by the ingress-nginx validating admission controller being susceptible to memory consumption due to large incoming requests.
Which versions of ingress-nginx are affected by CVE-2026-24514?
CVE-2026-24514 affects all versions of ingress-nginx that implement the validating admission controller feature.
Can CVE-2026-24514 be exploited remotely?
Yes, CVE-2026-24514 can be exploited remotely by an attacker who sends large requests to trigger the denial of service.