Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
14 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.74% | — | Kubernetes Ingress-nginx | 9/3/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller.… | |
| Aplazada | Alta (8.8) | 0.53% | — | Kubernetes Ingress-nginxAI | 6/2/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the… | |
| Aplazada | Alta (8.8) | 30% | — | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the… | |
| Aplazada | Media (4.8) | 3.3% | — | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with… | |
| Aplazada | Alta (8.8) | 82% | — | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure… | |
| Aplazada | Alta (8.8) | 33% | — | Kubernetes Ingress-nginxAI | 25/3/2025 | 17/6/2026 | A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to… | |
| Modificada | Alta (8.8) | 57% | — | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation. | |
| Modificada | Alta (8.8) | 2.2% | — | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress nginx annotation injection causes arbitrary command execution. | |
| Modificada | Media (6.5) | 1.6% | — | Kubernetes Ingress-nginx | 25/10/2023 | 17/6/2026 | Ingress-nginx `path` sanitization can be bypassed with `log_format` directive. | |
| Modificada | Media (6.5) | 0.69% | — | Kubernetes Ingress-nginx | 24/5/2023 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the… | |
| Modificada | Alta (7.1) | 1.4% | — | Kubernetes Ingress-nginx | 6/5/2022 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has… | |
| Modificada | Alta (8.1) | 1.2% | — | Kubernetes Ingress-nginx | 6/5/2022 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that… | |
| Modificada | Alta (7.1) | 2.1% | — | Kubernetes Ingress-nginxNetapp Trident | 29/10/2021 | 17/6/2026 | A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster. | |
| Modificada | Media (5.9) | 0.89% | — | Kubernetes Ingress-nginx | 29/7/2020 | 17/6/2026 | The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name. |