CVE-2026-4342 is a high-severity vulnerability in ingress-nginx, allowing attackers to inject arbitrary configuration into nginx through specially crafted Ingress annotations. This flaw, rated 8.8 CVSS, can lead to arbitrary code execution within the ingress-nginx controller and disclosure of all cluster-wide Secrets accessible to it. Exploitation requires only low privileges and network access, with low attack complexity. While there is no evidence of active exploitation or public exploit code, its significant potential impact necessitates prompt remediation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, < 1.13.9CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* | ||
>= 0, < 1.14.5CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* | ||
>= 0, < 1.15.1CPE match | cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:* | ||
< 1.13.9CPE matchmatch criteria | cpe:2.3:a:kubernetes:nginx_ingress_controller:*:*:*:*:*:*:*:* | ||
>= 1.14.0, < 1.14.5CPE matchmatch criteria | cpe:2.3:a:kubernetes:nginx_ingress_controller:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
ingress-nginx comment-based nginx configuration injection
Mar 20, 2026ingress-nginx comment-based nginx configuration injection
Mar 20, 2026ingress-nginx comment-based nginx configuration injection
ingress-nginx comment-based nginx configuration injection
ingress-nginx comment-based nginx configuration injection