VendorsKubernetesingress-nginxany version
Vulnerabilities

Kubernetes Ingress-nginx any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-5044
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation
Published 2023-10-25 · Modified
8.8EPSS 0.566
CVE-2026-3288
ingress-nginx rewrite-target nginx configuration injection
Published 2026-03-09 · Analyzed
8.8EPSS 0.063
CVE-2023-5043
Ingress nginx annotation injection causes arbitrary command execution
Published 2023-10-25 · Modified
8.8EPSS 0.022
CVE-2022-4886
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive
Published 2023-10-25 · Modified
8.8EPSS 0.016
CVE-2021-25745
Ingress-nginx path can be pointed to service account token file
Published 2022-05-06 · Modified
8.1EPSS 0.012
CVE-2021-25742
Ingress-nginx custom snippets allows retrieval of ingress-nginx serviceaccount token and secrets across all namespaces
Published 2021-10-29 · Modified
7.6EPSS 0.021
CVE-2021-25746
Ingress-nginx directive injection via annotations
Published 2022-05-06 · Modified
7.6EPSS 0.014
CVE-2021-25748
Ingress-nginx `path` sanitization can be bypassed with newline character
Published 2023-05-24 · Modified
7.6EPSS 0.007
CVE-2020-8553
Kubernetes ingress-nginx Compromise of auth via subset/superset namespace names
Published 2020-07-29 · Modified
5.9EPSS 0.009