Junglewise Threat Intelligence

CVE-2026-1580: GO-2026-4423 - ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx in k8s.io/ingres

CVE-2026-1580 · Severity: low · CVSS 3.1 · Published 2026-02-05

Technologies: k8s.io/ingress-nginx (Go). Vendors: Go.

Executive brief

ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx in k8s.io/ingress-nginx

Affected products

  • Go k8s.io/ingress-nginx

Related threats