Junglewise Threat Intelligence

CVE-2026-24512: GO-2026-4426 - ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginx in k8s.io/ingress-nginx

CVE-2026-24512 · Severity: low · CVSS 3.1 · Published 2026-02-05

Technologies: k8s.io/ingress-nginx (Go). Vendors: Go.

Executive brief

ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginx in k8s.io/ingress-nginx

Affected products

  • Go k8s.io/ingress-nginx

Related threats