Skip to main content

Vendor/product archive

kubernetes / ingress-nginx CVEs

Beta · best-effort

9 CVEs tagged to kubernetes / ingress-nginx0 Critical, 8 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-3288

Published Mar 9, 2026

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can…

CVSS 8.8 · High
evidence mentions
4
Buzz score
27.6
Vendor/product tagsBeta · best-effort

CVE-2021-25748

Published May 24, 2023

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[]…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25746

Published May 6, 2022

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.i…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25745

Published May 6, 2022

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in t…

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25742

Published Oct 29, 2021

A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.

CVSS 7.6 · High
Vendor/product tagsBeta · best-effort

CVE-2020-8553

Published Jul 29, 2020

The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1