VulnSea

k8s.io/ingress-nginx vulnerabilities

CVEs whose affected-version data names the k8s.io/ingress-nginx package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-24513Low· 3.1
7mo ago

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

ingress-nginx has Improper Check for Unusual or Exceptional Conditions

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.32%via OSV
CVE-2026-24514Medium· 6.5PoC
7mo ago

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 0.49%via OSV
CVE-2025-1097High· 8.8PoC
1y ago

ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 33%via OSV
CVE-2025-24513Medium· 4.8
1y ago

ingress-nginx controller - auth secret file path traversal vulnerability

ingress-nginx controller - auth secret file path traversal vulnerability

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 3.3%via OSV
CVE-2022-4886High· 8.8
2y ago

Ingress-nginx path sanitization can be bypassed

Ingress-nginx path sanitization can be bypassed

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 1.6%via OSV
CVE-2023-5043High· 7.6PoC
2y ago

Ingress nginx annotation injection causes arbitrary command execution

Ingress nginx annotation injection causes arbitrary command execution

▾ Midnightingress-nginx · k8s.io/ingress-nginxEPSS 2.2%via OSV
CVE-2021-25748Medium· 6.5
3y ago

Ingress-nginx `path` sanitization can be bypassed with newline character

Ingress-nginx `path` sanitization can be bypassed with newline character

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.69%via OSV
CVE-2018-1002104Medium· 5.3
4y ago

Kubernetes ingress exposes sensitive information

Kubernetes ingress exposes sensitive information

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 1.1%via OSV
CVE-2020-8553Medium· 5.9
4y ago

ingress-nginx component for Kubernetes allows file overwrite

ingress-nginx component for Kubernetes allows file overwrite

▾ Sunlitingress-nginx · k8s.io/ingress-nginxEPSS 0.89%via OSV
CVE-2021-25745High· 8.1
4y ago

Improper Input Validation in k8s.io/ingress-nginx

Improper Input Validation in k8s.io/ingress-nginx

▾ Twilightingress-nginx · k8s.io/ingress-nginxEPSS 1.2%via OSV
k8s.io/ingress-nginx vulnerabilities (CVEs) · VulnSea