SB2026090742 - Improper neutralization of equivalent special elements in NGINX Ingress Controller
Published: September 7, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper neutralization of equivalent special elements (CVE-ID: CVE-2026-77180)
CWE-ID: CWE-76 - Improper Neutralization of Equivalent Special Elements
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.
The vulnerability exists due to improper neutralization of equivalent special elements in the NGINX Ingress Controller configuration generator when processing Ingress annotation values. A remote user can submit crafted annotation values to inject arbitrary NGINX configuration directives.
The issue is limited to the control plane and has no data plane exposure.
Remediation
Install update from vendor's website.