VendorsKubernetesnginx_ingress_controllerany version
Vulnerabilities

Kubernetes Nginx Ingress Controller any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2026-4342
ingress-nginx comment-based nginx configuration injection
Published 2026-03-19 · Analyzed
8.8EPSS 0.015
CVE-2018-1002104
Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prometheus metrics publicly.
Published 2020-01-14 · Modified
5.3EPSS 0.011