ingress-nginx has 10 CVEs on record between 2022 and 2026. The median CVSS is 6.5 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.5
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- k8s.io/ingress-nginx 10
Worst active — by depth score
CVE-2025-1097High· 8.8ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation68CVE-2023-5043High· 7.6Ingress nginx annotation injection causes arbitrary command execution54CVE-2022-4886High· 8.8Ingress-nginx path sanitization can be bypassed49CVE-2026-24514Medium· 6.5ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling 48CVE-2021-25745High· 8.1Improper Input Validation in k8s.io/ingress-nginx45
ingress-nginx vulnerabilities
CVEs affecting ingress-nginx, newest first. Open any entry for full detail, references, and exploit status.
10 CVEsRSS
CVE-2026-24513Low· 3.1ingress-nginx has Improper Check for Unusual or Exceptional Conditions
ingress-nginx has Improper Check for Unusual or Exceptional Conditions
CVE-2026-24514Medium· 6.5PoCingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling
CVE-2025-1097High· 8.8PoCngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation
CVE-2025-24513Medium· 4.8ingress-nginx controller - auth secret file path traversal vulnerability
ingress-nginx controller - auth secret file path traversal vulnerability
CVE-2022-4886High· 8.8Ingress-nginx path sanitization can be bypassed
Ingress-nginx path sanitization can be bypassed
CVE-2023-5043High· 7.6PoCIngress nginx annotation injection causes arbitrary command execution
Ingress nginx annotation injection causes arbitrary command execution
CVE-2021-25748Medium· 6.5Ingress-nginx `path` sanitization can be bypassed with newline character
Ingress-nginx `path` sanitization can be bypassed with newline character
CVE-2018-1002104Medium· 5.3Kubernetes ingress exposes sensitive information
Kubernetes ingress exposes sensitive information
CVE-2020-8553Medium· 5.9ingress-nginx component for Kubernetes allows file overwrite
ingress-nginx component for Kubernetes allows file overwrite
CVE-2021-25745High· 8.1Improper Input Validation in k8s.io/ingress-nginx
Improper Input Validation in k8s.io/ingress-nginx