SB2026090742 - Improper neutralization of equivalent special elements in NGINX Ingress Controller



SB2026090742 - Improper neutralization of equivalent special elements in NGINX Ingress Controller

Published: September 7, 2026

Security Bulletin ID SB2026090742
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper neutralization of equivalent special elements (CVE-ID: CVE-2026-77180)

CWE-ID: CWE-76 - Improper Neutralization of Equivalent Special Elements

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.

The vulnerability exists due to improper neutralization of equivalent special elements in the NGINX Ingress Controller configuration generator when processing Ingress annotation values. A remote user can submit crafted annotation values to inject arbitrary NGINX configuration directives.

The issue is limited to the control plane and has no data plane exposure.


Remediation

Install update from vendor's website.