https://seclists.org/oss-sec/2026/q1/353: [kubernetes] CVE-2026-4342: ingss-nginx comment-based nginx configuration injection
Published Mar 19, 2026
·Updated
Affected Software
1 affected component
Kubernetes ingress-nginx<1.13.9, <1.14.5, <1.15.1
Frequently Asked Questions
1
What is the severity of CVE-2026-4342?
CVE-2026-4342 is considered a high-severity vulnerability due to the potential for arbitrary code execution.
2
How do I fix CVE-2026-4342?
To fix CVE-2026-4342, upgrade to the latest version of the ingress-nginx controller where the issue has been addressed.
3
What are the potential impacts of CVE-2026-4342?
CVE-2026-4342 can lead to arbitrary code execution within the ingress-nginx controller and potential disclosure of sensitive Secrets.
4
Which versions of Kubernetes ingress-nginx are affected by CVE-2026-4342?
CVE-2026-4342 affects specific earlier versions of the Kubernetes ingress-nginx controller before the security fix was implemented.
5
Is CVE-2026-4342 related to configuration management in Kubernetes?
Yes, CVE-2026-4342 relates to misconfigured Ingress annotations that can be exploited for configuration injection.