« Volver al listado

Kubernetes

Kubernetes Ingress-nginx: vulnerabilidades y CVE

Kubernetes Ingress-nginx tiene 14 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE14
Últimos 12 meses2
Críticas0
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-3288Alta (8.8)0.71%—9 mar 2026
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the…
CVE-2025-15566Alta (8.8)0.53%—6 feb 2026
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-proxy-set-headers` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code…
CVE-2025-24514Alta (8.8)30%—25 mar 2025
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-url` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code…
CVE-2025-24513Media (4.8)3.3%—25 mar 2025
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in…
CVE-2025-1098Alta (8.8)82%—25 mar 2025
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `mirror-target` and `mirror-host` Ingress annotations can be used to inject arbitrary configuration into nginx. This…
CVE-2025-1097Alta (8.8)33%—25 mar 2025
A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where the `auth-tls-match-cn` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary…
CVE-2023-5044Alta (8.8)57%—25 oct 2023
Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.
CVE-2023-5043Alta (8.8)2.2%—25 oct 2023
Ingress nginx annotation injection causes arbitrary command execution.
CVE-2022-4886Media (6.5)1.6%—25 oct 2023
Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.
CVE-2021-25748Media (6.5)0.69%—24 may 2023
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the sanitization of the `spec.rules[].http.paths[].path` field of an Ingress…
CVE-2021-25746Alta (7.1)1.4%—6 may 2022
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress object (in the networking.k8s.io or extensions API group) to obtain the…
CVE-2021-25745Alta (8.1)1.2%—6 may 2022
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API…
CVE-2021-25742Alta (7.1)2.1%—29 oct 2021
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain all secrets in the cluster.
CVE-2020-8553Media (5.9)0.89%—29 jul 2020
The Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress objects to overwrite the password file of another ingress which uses…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1059 Command and Scripting Interpreter5
  2. T1210 Exploitation of Remote Services5

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Kubernetes