CVE-2026-1580: 
Ingress NGINX Controller (community-driven) vulnerability analysis and mitigation

Overview

CVE-2026-1580 is a configuration injection vulnerability in Kubernetes ingress-nginx where the nginx.ingress.kubernetes.io/auth-method Ingress annotation can be used to inject arbitrary configuration into nginx, leading to remote code execution and Secret disclosure. It was disclosed on February 2–3, 2026, and affects ingress-nginx versions prior to v1.13.7 and prior to v1.14.3. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Kubernetes Issue).

Technical details

The root cause is improper input validation (CWE-20) of the nginx.ingress.kubernetes.io/auth-method Ingress annotation value, which is incorporated unsanitized into the nginx configuration generated by the ingress-nginx controller. An authenticated attacker with low privileges — sufficient to create or modify Ingress resources in the cluster — can craft a malicious annotation value containing nginx configuration directives or newline-injected blocks that alter the controller's nginx configuration. This allows the attacker to execute arbitrary code within the ingress-nginx controller process and access Kubernetes Secrets the controller can reach (GitHub Advisory, Kubernetes Issue).

Impact

Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the ingress-nginx controller and disclose Kubernetes Secrets accessible to it. In the default ingress-nginx installation, the controller's service account has cluster-wide read access to all Secrets, meaning a successful attack can expose credentials, API tokens, TLS certificates, and other sensitive data across the entire cluster. This represents a critical control plane risk with high impact on confidentiality, integrity, and availability, and could enable lateral movement or full cluster compromise (GitHub Advisory, Kubernetes Issue).

Exploitability

As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.095% (19th percentile), indicating a currently low probability of exploitation in the near term. The vulnerability requires low privileges (ability to create or modify Ingress resources) but no user interaction, making it accessible to any cluster tenant with Ingress creation rights. The vulnerability was discovered by the Volcengine Security Team and coordinated by the Kubernetes Security Response Committee (Kubernetes Issue). There is no indication it has been added to the CISA KEV catalog.

Exploitation steps

  1. Reconnaissance: Identify a target Kubernetes cluster running ingress-nginx versions prior to v1.13.7 or v1.14.3 using kubectl get pods --all-namespaces --selector app.kubernetes.io/name=ingress-nginx.
  2. Obtain low-privilege access: Acquire credentials or a service account with permission to create or modify Ingress resources in at least one namespace (e.g., a developer or CI/CD account).
  3. Craft malicious annotation: Create or patch an Ingress resource with a specially crafted nginx.ingress.kubernetes.io/auth-method annotation value that injects additional nginx configuration directives — for example, using newline characters to break out of the expected context and insert arbitrary nginx location blocks or lua_code_cache directives.
  4. Trigger configuration reload: The ingress-nginx controller watches for Ingress changes and automatically regenerates and reloads the nginx configuration, incorporating the injected directives.
  5. Achieve code execution: The injected nginx configuration executes arbitrary commands or loads attacker-controlled code within the controller process context.
  6. Exfiltrate Secrets: Use the controller's cluster-wide Secret access (default configuration) to read Kubernetes Secrets via the controller's service account, extracting credentials, tokens, or certificates (GitHub Advisory, Kubernetes Issue).

Indicators of compromise

  • Kubernetes API / Audit Logs: Ingress resources created or modified with unusual or unexpected values in the nginx.ingress.kubernetes.io/auth-method annotation, particularly values containing newline characters (\n), semicolons, or nginx directive keywords.
  • ingress-nginx Controller Logs: Unexpected nginx configuration reload errors or warnings; unusual nginx configuration content logged during template rendering; errors referencing malformed auth_request or related directives.
  • Process Behavior: Unexpected child processes spawned by the nginx or ingress-nginx controller process (e.g., curl, wget, bash, sh, python).
  • Network: Unusual outbound connections from the ingress-nginx controller pod to external IPs or internal cluster services not associated with normal ingress traffic.
  • Kubernetes Secret Access: Audit log entries showing the ingress-nginx controller service account accessing Secrets beyond its normal operational scope or in unusual namespaces (Kubernetes Issue).

Mitigation and workarounds

Upgrade ingress-nginx to v1.13.7 or v1.14.3 (or later), which contain the fix for this vulnerability (GitHub Advisory, Kubernetes Issue). As a pre-upgrade workaround, deploy a validating admission controller (e.g., OPA/Gatekeeper or Kyverno) to reject Ingress resources containing the nginx.ingress.kubernetes.io/auth-method annotation. Additionally, restrict RBAC permissions so that only trusted users and service accounts can create or modify Ingress resources, and limit the ingress-nginx controller's Secret access to only the Secrets it strictly requires rather than cluster-wide access.

Community reactions

The vulnerability was covered by CSO Online and Network World as part of a broader report on four new ingress-nginx vulnerabilities (CSO Online). The runZero blog published a technical analysis of the Kubernetes ingress-nginx controller vulnerabilities (runZero Blog). Datadog Security Labs also published commentary in the context of ingress-nginx's broader retirement announcement (Datadog Security Labs). CISA included the vulnerability in its weekly bulletin (SB26-040), and national CERTs including CERT.at, CSA Singapore, and Belgium's CCB issued advisories. The Hacker Wire covered the RCE angle on social media and its website (The Hacker Wire).

Additional resources


Source: This report was generated using AI

Related Ingress NGINX Controller (community-driven) vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-4342HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesMar 19, 2026
CVE-2026-3288HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesMar 09, 2026
CVE-2025-15566HIGH8.8
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesFeb 06, 2026
CVE-2026-24514MEDIUM6.5
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • ingress-nginx-controller-fips-1.14
NoYesFeb 03, 2026
CVE-2026-24513LOW3.1
  • Ingress NGINX Controller (community-driven) logoIngress NGINX Controller (community-driven)
  • cpe:2.3:a:kubernetes:ingress-nginx
NoYesFeb 03, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management