HIGH🇵🇱 Wersja polska

CVE-2026-4342

CVSS 8.8v3.1pub. 2026-03-19upd. 2026-05-19

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Kubernetes nginx Ingress Controller

    APP
    Kubernetes
    1.15.0< 1.13.91.14.0 – 1.14.5 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2018-1002104MEDIUM5.3same product

Versions < 1.5 of the Kubernetes ingress default backend, which handles invalid ingress traffic, exposed prome...

CVE-2026-13019CRITICAL9.8PL ✓same vendor

Esri Portal for ArcGIS – brak uwierzytelnienia dla krytycznej funkcji API

CVE-2026-33519CRITICAL9.8PL ✓same vendor

Nieprawidłowa autoryzacja w Esri Portal for ArcGIS — obejście uprawnień

CVE-2025-57870CRITICAL10.0PL ✓same vendor

SQL Injection w Esri ArcGIS Server — zdalny dostęp bez uwierzytelnienia

CVE-2023-1174CRITICAL9.8PL ✓same vendor

Nieautoryzowany zdalny dostęp do kontenera Minikube przez otwarty port sieciowy