CVE-2026-4342: ingress-nginx comment-based nginx configuration injection

Published Mar 19, 2026
·
Updated

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Affected Software

5 affected componentsFixes available
ingress-nginx ingress-nginx
go/k8s.io/ingress-nginx<0.0.0-20260319175635-5183b7d86137
0.0.0-20260319175635-5183b7d86137
Kubernetes Nginx Ingress Controller<1.13.9
Kubernetes Nginx Ingress Controller>=1.14.0<1.14.5
Kubernetes Nginx Ingress Controller=1.15.0

Event History

Mar 19, 2026
CVE Published
via MITRE·09:50 PM
Data Sourced
via MITRE·09:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 PM
Affected Software
Mar 20, 2026
Advisory Published
via GitHub·12:31 AM
Data Sourced
via GitHub·12:31 AM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-4342?

CVE-2026-4342 is considered to have a critical severity level due to its potential for arbitrary code execution.

2

How do I fix CVE-2026-4342?

You can mitigate CVE-2026-4342 by upgrading to the remedial version of ingress-nginx, specifically version 0.0.0-20260319175635-5183b7d86137 or later.

3

What causes CVE-2026-4342?

CVE-2026-4342 is caused by a combination of Ingress annotations that lead to improper handling of nginx configuration in ingress-nginx.

4

What are the consequences of CVE-2026-4342?

Exploiting CVE-2026-4342 can lead to arbitrary code execution in the context of the ingress-nginx controller, resulting in severe security breaches.

5

Is CVE-2026-4342 exploitable in all ingress-nginx versions?

CVE-2026-4342 is exploitable in versions of ingress-nginx prior to the fixed version 0.0.0-20260319175635-5183b7d86137.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203