Executive brief
A vulnerability was found in the Kubernetes ingress-nginx controller, which manages external access to services in a cluster. An attacker with permission to create or modify Ingress objects can inject malicious configuration settings. This could allow them to execute unauthorized code or steal sensitive information, such as passwords and API keys, from across the entire cluster.
Technical details
A configuration injection vulnerability exists in ingress-nginx due to improper validation of Ingress annotations. An attacker with low-privileged 'create' or 'patch' permissions on Ingress resources can use specific annotation combinations to inject arbitrary directives into the generated nginx configuration. This can be leveraged to achieve arbitrary code execution within the context of the ingress-nginx controller pod. Because the controller often runs with broad permissions, an attacker may also be able to retrieve all Kubernetes Secrets accessible to the controller, which in default installations includes cluster-wide access. The issue is addressed in versions 1.13.9, 1.14.5, and 1.15.1.
Affected products
- Kubernetes ingress-nginx < 1.13.9, 1.14.0 to < 1.14.5, 1.15.0
Timeline
- 2026-03-19: disclosed
- 2026-03-19: advisory
- 2026-03-19: patched