CVE-2026-77180
Received Received - Intake

NGINX Ingress Controller Configuration Injection Vulnerability

Vulnerability report for CVE-2026-77180, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-02

Last updated on: 2026-09-02

Assigner: F5 Networks

Description

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-02
Last Modified
2026-09-02
Generated
2026-09-02
AI Q&A
2026-09-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
nginx ingress_controller *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-76 The product correctly neutralizes certain special elements, but it improperly neutralizes equivalent special elements.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an injection flaw in the NGINX Ingress Controller's configuration generator. When users configure Ingress annotations in Kubernetes, the system writes user-controlled input directly into the NGINX configuration without proper sanitization. An attacker with write access to these annotations could inject malicious NGINX directives into the configuration.

Impact Analysis

An attacker with permission to modify Ingress annotations could inject arbitrary NGINX configuration, potentially creating or deleting files, disabling services, or altering the behavior of the NGINX Ingress Controller. This is a control plane issue and does not directly expose the data plane.

Mitigation Strategies

Review and restrict write access to NGINX Ingress Controller Ingress annotations in Kubernetes. Ensure only authorized users can modify these annotations. Update to a patched version of NGINX Ingress Controller if available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77180. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart