Improper neutralization of equivalent special elements in NGINX Ingress Controller - CVE-2026-77180

 

Improper neutralization of equivalent special elements in NGINX Ingress Controller - CVE-2026-77180

Published: September 7, 2026


Vulnerability identifier: #VU147231
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-77180
CWE-ID: CWE-76
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.

The vulnerability exists due to improper neutralization of equivalent special elements in the NGINX Ingress Controller configuration generator when processing Ingress annotation values. A remote user can submit crafted annotation values to inject arbitrary NGINX configuration directives.

The issue is limited to the control plane and has no data plane exposure.


Affected software

NGINX Ingress Controller

How to mitigate CVE-2026-77180

Install security update from vendor's website.

NGINX Ingress Controller - addressed in versions 5.6.0, 2026-lts-r5

External References

Related Security Bulletins