CVE-2026-1580
Unknown
Unknown - Not Provided
Arbitrary Code Execution via Ingress Annotation in ingress-nginx
Publication date: 2026-02-03
Last updated on: 2026-02-03
Assigner: Kubernetes
Description
Description
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ingress-nginx | ingress-nginx | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-20 | The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in ingress-nginx where the Ingress annotation `nginx.ingress.kubernetes.io/auth-method` can be exploited to inject arbitrary configuration into nginx.
As a result, an attacker can execute arbitrary code within the context of the ingress-nginx controller.
Additionally, the attacker can gain access to Secrets that the controller can access, which by default includes all Secrets cluster-wide.
How can this vulnerability impact me? :
This vulnerability can have severe impacts including:
- Arbitrary code execution within the ingress-nginx controller, potentially allowing full control over the controller.
- Disclosure of sensitive information by accessing Secrets that the controller has access to, which may include credentials or other confidential data.
- Potential disruption of services due to the compromise of the ingress controller.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
I don't know
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70