Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.74%—Kubernetes Ingress-nginx9/3/202617/6/2026
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller.…
AplazadaAlta (8.8)0.53%—Kubernetes Ingress-nginxAI6/2/202617/6/2026
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the…
AplazadaAlta (8.8)30%—Kubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the…
AplazadaMedia (4.8)3.3%—Kubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with…
AplazadaAlta (8.8)82%—Kubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure…
AplazadaAlta (8.8)33%—Kubernetes Ingress-nginxAI25/3/202517/6/2026
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to…
ModificadaAlta (8.8)57%—Kubernetes Ingress-nginx25/10/202317/6/2026
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
ModificadaAlta (8.8)2.2%—Kubernetes Ingress-nginx25/10/202317/6/2026
Ingress nginx annotation injection causes arbitrary command execution.
ModificadaMedia (6.5)1.6%—Kubernetes Ingress-nginx25/10/202317/6/2026
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
ModificadaMedia (6.5)0.69%—Kubernetes Ingress-nginx24/5/202317/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress object (in the `networking.k8s.io` or `extensions` API group) to obtain the credentials of the…
ModificadaAlta (7.1)1.4%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has…
ModificadaAlta (8.1)1.2%—Kubernetes Ingress-nginx6/5/202217/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that…
ModificadaAlta (7.1)2.1%—Kubernetes Ingress-nginxNetapp Trident29/10/202117/6/2026
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
ModificadaMedia (5.9)0.89%—Kubernetes Ingress-nginx29/7/202017/6/2026
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses nginx.ingress.kubernetes.io/auth-type: basic and which has a hyphenated namespace or secret name.