A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
References
| Link | Resource |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/137893 | Issue Tracking |
| http://www.openwall.com/lists/oss-security/2026/03/19/9 | Mailing List Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
19 May 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Kubernetes nginx Ingress Controller
|
|
| CPE | cpe:2.3:a:kubernetes:ingress-nginx:1.15.0:*:*:*:*:*:*:* |
cpe:2.3:a:kubernetes:nginx_ingress_controller:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:kubernetes:nginx_ingress_controller:*:*:*:*:*:*:*:* |
28 Apr 2026, 21:56
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/kubernetes/kubernetes/issues/137893 - Issue Tracking | |
| References | () http://www.openwall.com/lists/oss-security/2026/03/19/9 - Mailing List, Third Party Advisory | |
| CWE | NVD-CWE-noinfo | |
| Summary |
|
|
| CPE | cpe:2.3:a:kubernetes:ingress-nginx:1.15.0:*:*:*:*:*:*:* cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* |
|
| First Time |
Kubernetes ingress-nginx
Kubernetes |
19 Mar 2026, 22:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-03-19 22:16
Updated : 2026-05-19 22:16
NVD link : CVE-2026-4342
Mitre link : CVE-2026-4342
CVE.ORG link : CVE-2026-4342
JSON object : View
Products Affected
kubernetes
- nginx_ingress_controller
CWE
