CVE-2024-7646
Ingress NGINX Controller (community-driven) vulnerability analysis and mitigation

Overview

A critical security vulnerability (CVE-2024-7646) was discovered in ingress-nginx, affecting versions prior to v1.11.2. The vulnerability allows actors with permission to create Ingress objects in the networking.k8s.io or extensions API group to bypass annotation validation, enabling arbitrary command injection and unauthorized access to ingress-nginx controller credentials. The issue was discovered and reported by André Storfjord Kristiansen, and has been assigned a High severity CVSS score of 8.8 (Kubernetes Issue, OSS Security).

Technical details

The vulnerability stems from a flaw in the annotation validation process within ingress-nginx that allows malicious actors to bypass security controls. The issue received a CVSS v3.1 score of 8.8 (High) with the vector string CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility, low attack complexity, and high impact on confidentiality, integrity, and availability. The vulnerability is classified as CWE-20 (Improper Input Validation) (Security Online, Kubernetes Issue).

Impact

In the default configuration, successful exploitation of this vulnerability provides access to all secrets within the Kubernetes cluster through the compromised ingress-nginx controller credentials. This poses a particularly significant risk in multi-tenant environments where non-admin users have permissions to create Ingress objects (Kubernetes Announce, Security Online).

Exploitability

The vulnerability can be exploited by creating Ingress objects with specially crafted annotations that contain carriage returns (\r). The attack requires network access and low complexity to execute, making it relatively straightforward for attackers with the necessary permissions to exploit (Kubernetes Issue, OSS Security).

Mitigation and workarounds

The primary mitigation is to upgrade to ingress-nginx controller v1.11.2, which contains the security fixes implemented in PRs #11719 and #11721. Organizations should also review their Kubernetes audit logs for Ingress objects with annotations (particularly nginx.ingress.kubernetes.io/auth-tls-verify-client) containing carriage returns, as these may indicate exploitation attempts (Kubernetes Issue, Security Online).

Additional resources


SourceThis report was generated using AI

Related Ingress NGINX Controller (community-driven) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-4342HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesMar 19, 2026
CVE-2026-3288HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesMar 09, 2026
CVE-2025-15566HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesFeb 06, 2026
CVE-2026-24514MEDIUM6.5
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • k8s.io/ingress-nginx
NoYesFeb 03, 2026
CVE-2026-24513LOW3.1
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • ingress-nginx-controller-1.13
NoYesFeb 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management