Code Injection in Ingress-NGINX Controller for Kubernetes - CVE-2026-24512

 

Code Injection in Ingress-NGINX Controller for Kubernetes - CVE-2026-24512

Published: February 4, 2026


Vulnerability identifier: #VU122287
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-24512
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to compromise the affected system.

The vulnerability exists due to improper input validation where the rules.http.paths.path Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller.



Affected software

Ingress-NGINX Controller for Kubernetes

How to mitigate CVE-2026-24512

Install updates from vendor's website.

Ingress-NGINX Controller for Kubernetes - addressed in versions 1.13.7, 1.14.3

External References

Related Security Bulletins