VendorsF5nginx_ingress_controllerany version
Vulnerabilities

F5 NGINX Ingress Controller any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

24CVEs
CVE-2026-42945
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-13 · Modified
9.2EPSS 0.034
CVE-2026-9256
NGINX ngx_http_rewrite_module vulnerability
Published 2026-05-22 · Modified
9.2EPSS 0.027
CVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.024
CVE-2026-42530
NGINX Open-Source ngx_http_v3_module vulnerability
Published 2026-06-17 · Modified
9.2EPSS 0.011
CVE-2026-42533
NGINX Map directive and Regex matching vulnerability
Published 2026-07-15 · Analyzed
9.2EPSS 0.009
CVE-2026-60005
NGINX ngx_http_slice_module vulnerability
Published 2026-07-15 · Analyzed
8.8EPSS 0.005
CVE-2026-55723
NGINX Ingress Controller vulnerability
Published 2026-07-15 · Analyzed
8.7EPSS 0.005
CVE-2026-42946
NGINX ngx_http_scgi_module and ngx_http_uwsgi_module vulnerability
Published 2026-05-13 · Analyzed
8.3EPSS 0.005
CVE-2026-56434
NGINX ngx_http_ssi_module vulnerability
Published 2026-07-15 · Analyzed
8.3EPSS 0.004
CVE-2026-1642
NGINX vulnerability
Published 2026-02-04 · Analyzed
8.2EPSS 0.004
CVE-2022-41741
NGINX ngx_http_mp4_module vulnerability CVE-2022-41741
Published 2022-10-19 · Modified
7.8EPSS 0.008
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2022-41742
NGINX ngx_http_mp4_module vulnerability CVE-2022-41742
Published 2022-10-19 · Modified
7.1EPSS 0.011
CVE-2026-52865
NGINX Ingress Controller vulnerability
Published 2026-07-15 · Analyzed
7.1EPSS 0.005
CVE-2022-41743
NGINX ngx_http_hls_module vulnerability CVE-2022-41743
Published 2022-10-19 · Modified
7.0EPSS 0.002
CVE-2026-40460
NGINX ngx_quic_module vulnerability
Published 2026-05-13 · Analyzed
6.9EPSS 0.004
CVE-2021-23055
On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published 2022-04-21 · Modified
6.5EPSS 0.008
CVE-2022-30535
NGINX Ingress Controller vulnerability CVE-2022-30535
Published 2022-08-04 · Modified
6.5EPSS 0.007
CVE-2026-60065
NGINX Plus ngx_stream_mqtt_filter_module vulnerability
Published 2026-07-15 · Analyzed
6.3EPSS 0.004
CVE-2026-48142
NGINX ngx_http_charset_module vulnerability
Published 2026-06-17 · Analyzed
6.3EPSS 0.004
CVE-2026-42934
NGINX ngx_http_charset_module vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.004
CVE-2026-40701
NGINX ngx_http_ssl_module vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.003
CVE-2026-42926
NGINX ngx_http_proxy_v2_module vulnerability
Published 2026-05-13 · Analyzed
6.3EPSS 0.003
CVE-2024-10318
NGINX OpenID Connect Vulnerability
Published 2024-11-06 · Analyzed
5.4EPSS 0.003