Executive brief
NGINX Ingress Controller is a widely-used tool for managing HTTP and HTTPS traffic routing in Kubernetes clusters. An authenticated attacker with write permissions to Ingress annotations can inject arbitrary NGINX configuration directives, potentially creating or deleting files or disabling services. The vulnerability is limited to control-plane operations and does not expose the actual data traffic being routed.
Technical details
This is a configuration injection vulnerability in the NGINX Ingress Controller's configuration generator. Multiple user-controllable fields from Ingress annotations are written into the generated NGINX configuration file without proper sanitization. An authenticated attacker with permission to create or modify Ingress objects through the Kubernetes API can craft malicious annotation values that break out of their intended context and inject arbitrary NGINX directives. The attack requires valid Kubernetes API credentials and write access to Ingress resources; it does not affect the data plane or exposed services directly. Patches are expected to be available from the vendor.
Affected products
- NGINX Ingress Controller
Timeline
- 2026-09-02: disclosed