Skip to main content

Vendor/product archive

f5 / nginx_ingress_controller CVEs

Beta · best-effort

19 CVEs tagged to f5 / nginx_ingress_controller3 Critical, 8 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-55723

Published Jul 15, 2026

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGI…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-52865

Published Jul 15, 2026

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer reso…

CVSS 7.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-42055

Published Jun 17, 2026

NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2…

CVSS 9.2 · Critical
evidence mentions
14
Buzz score
47.1

CVE-2025-14727

Published Dec 17, 2025

A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS)…

CVSS 8.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-30535

Published Aug 4, 2022

In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-23055

Published Apr 21, 2022

On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: So…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-19 of 19 CVEsPage 1 of 1