Where
-Infinity
0
Severity
8.8
EPSS
0.04%
Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/rewrite-target Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

First published (updated )

Hello Kubernetes Community,

A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/rewrite-target Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

This issue has been rated HIGH (CVSS calculator, score: 8.8), and assigned CVE-2026-3288

Am I vulnerable?

This issue affects ingress-nginx. If you do not have ingress-nginx installed on your cluster, you are not affected. You can check this by running kubectl get pods --all-namespaces --selector app.kubernetes.io/name=ingress-nginx.

Affected Versions

- ingress-nginx: < 1.13.8 - ingress-nginx: < 1.14.4 - ingress-nginx: < 1.15.0

How do I mitigate this vulnerability?

Prior to upgrading, this vulnerability can be mitigated by using admission control to block the use of the rewrite-target annotation.

Fixed Versions

- ingress-nginx: 1.13.8 - ingress-nginx: 1.14.4 - ingress-nginx: 1.15.0

How to upgrade?

To upgrade, refer to the documentation: Upgrading Ingress-nginx

Detection

Suspicious data within the rules.http.paths.path field of an Ingress resource could indicate an attempt to exploit this vulnerability.

If you find evidence that this vulnerability has been exploited, please contact security () kubernetes io

See the GitHub issue for more details: https://github.com/kubernetes/kubernetes/issues/137560

Acknowledgements

This vulnerability was reported by Kai Aizen

Thank You,

Tabitha Sable on behalf of the Kubernetes Security Response Committee

Severity
8.8
Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/auth-proxy-set-headers Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

First published (updated )
Severity
6.5
EPSS
0.01%
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

First published (updated )
Severity
8.8
Input Validation
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A security issue was discovered in ingress-nginx where the nginx.ingress.kubernetes.io/auth-method Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

First published (updated )

Hello Kubernetes Community,

Multiple issues are disclosed today in ingress-nginx, and assigned the following CVE IDs: CVE-2026-1580 <https://github.com/kubernetes/kubernetes/issues/136677>, CVE-2026-24512 <https://github.com/kubernetes/kubernetes/issues/136678>, CVE-2026-24513 <https://github.com/kubernetes/kubernetes/issues/136679>, CVE-2026-24514 <https://github.com/kubernetes/kubernetes/issues/136680>.

The most serious of these issues have been rated HIGH (CVSS calculator <https://www.first.org/cvss/calculator/3.1#CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H>, score: 8.8). Am I vulnerable?

This issue affects ingress-nginx. If you do not have ingress-nginx installed on your cluster, you are not affected. You can check this by running kubectl get pods --all-namespaces --selector app.kubernetes.io/name=ingress-nginx. Affected Versions

-

ingress-nginx: < v1.13.7 -

ingress-nginx: < v1.14.3

How do I mitigate this vulnerability?

ACTION REQUIRED: The following steps must be taken to mitigate this vulnerability: Upgrade ingress-nginx to v1.13.7, v1.14.3, or any later version.

Certain of these issues can be partially mitigated before patching. Please see their respective GitHub issues. Fixed Versions

-

ingress-nginx: v1.13.7 -

ingress-nginx: v1.14.3

How to upgrade?

To upgrade, refer to the documentation: Upgrading Ingress-nginx <https://kubernetes.github.io/ingress-nginx/deploy/upgrade/> Detection

Detection information for most of the vulns can be found in their respective GitHub issues.

If you find evidence that this vulnerability has been exploited, please contact security () kubernetes io Additional Details

For further information, please see the following GitHub issues:

-

CVE-2026-1580 <https://github.com/kubernetes/kubernetes/issues/136677> -

CVE-2026-24512 <https://github.com/kubernetes/kubernetes/issues/136678> -

CVE-2026-24513 <https://github.com/kubernetes/kubernetes/issues/136679> -

CVE-2026-24514 <https://github.com/kubernetes/kubernetes/issues/136680>

Thank You,

Tabitha Sable, on behalf of the Kubernetes Security Response Committee

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203