CVE-2026-52865: NGINX Ingress Controller vulnerability
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate.
Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.
Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-52865?
The severity of CVE-2026-52865 is medium with a CVSS score of 6.5.
What kind of impact can CVE-2026-52865 have?
CVE-2026-52865 can lead to the termination of the NGINX Ingress Controller process, affecting the control plane.
Who is affected by CVE-2026-52865?
CVE-2026-52865 affects authenticated remote attackers with permissions to create or modify Ingress or TransportServer resources.
How do I fix CVE-2026-52865?
To fix CVE-2026-52865, ensure that your NGINX Ingress Controller is updated to the latest version where the vulnerability is patched.
What type of vulnerability is CVE-2026-52865 classified as?
CVE-2026-52865 is classified as a Null Pointer Dereference vulnerability.