Vulnerabilities (CVE)

Filtered by vendor Kubernetes Subscribe
Filtered by product Nginx Ingress Controller
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-1002104 1 Kubernetes 1 Nginx Ingress Controller 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
CVE-2026-4342 1 Kubernetes 1 Nginx Ingress Controller 2026-05-19 N/A 8.8 HIGH
A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)