Improper neutralization of equivalent special elements in NGINX Ingress Controller - CVE-2026-77180
Published: September 7, 2026
Vulnerability details
The vulnerability allows a remote user to inject arbitrary NGINX configuration directives.
The vulnerability exists due to improper neutralization of equivalent special elements in the NGINX Ingress Controller configuration generator when processing Ingress annotation values. A remote user can submit crafted annotation values to inject arbitrary NGINX configuration directives.
The issue is limited to the control plane and has no data plane exposure.