
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1580 is a configuration injection vulnerability in Kubernetes ingress-nginx where the nginx.ingress.kubernetes.io/auth-method Ingress annotation can be used to inject arbitrary configuration into nginx, leading to remote code execution and Secret disclosure. It was disclosed on February 2–3, 2026, and affects ingress-nginx versions prior to v1.13.7 and prior to v1.14.3. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Kubernetes Issue).
The root cause is improper input validation (CWE-20) of the nginx.ingress.kubernetes.io/auth-method Ingress annotation value, which is incorporated unsanitized into the nginx configuration generated by the ingress-nginx controller. An authenticated attacker with low privileges — sufficient to create or modify Ingress resources in the cluster — can craft a malicious annotation value containing nginx configuration directives or newline-injected blocks that alter the controller's nginx configuration. This allows the attacker to execute arbitrary code within the ingress-nginx controller process and access Kubernetes Secrets the controller can reach (GitHub Advisory, Kubernetes Issue).
Successful exploitation allows an attacker to achieve arbitrary code execution in the context of the ingress-nginx controller and disclose Kubernetes Secrets accessible to it. In the default ingress-nginx installation, the controller's service account has cluster-wide read access to all Secrets, meaning a successful attack can expose credentials, API tokens, TLS certificates, and other sensitive data across the entire cluster. This represents a critical control plane risk with high impact on confidentiality, integrity, and availability, and could enable lateral movement or full cluster compromise (GitHub Advisory, Kubernetes Issue).
As of the time of disclosure, there is no public proof-of-concept exploit and no confirmed in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.095% (19th percentile), indicating a currently low probability of exploitation in the near term. The vulnerability requires low privileges (ability to create or modify Ingress resources) but no user interaction, making it accessible to any cluster tenant with Ingress creation rights. The vulnerability was discovered by the Volcengine Security Team and coordinated by the Kubernetes Security Response Committee (Kubernetes Issue). There is no indication it has been added to the CISA KEV catalog.
kubectl get pods --all-namespaces --selector app.kubernetes.io/name=ingress-nginx.nginx.ingress.kubernetes.io/auth-method annotation value that injects additional nginx configuration directives — for example, using newline characters to break out of the expected context and insert arbitrary nginx location blocks or lua_code_cache directives.nginx.ingress.kubernetes.io/auth-method annotation, particularly values containing newline characters (\n), semicolons, or nginx directive keywords.auth_request or related directives.curl, wget, bash, sh, python).Upgrade ingress-nginx to v1.13.7 or v1.14.3 (or later), which contain the fix for this vulnerability (GitHub Advisory, Kubernetes Issue). As a pre-upgrade workaround, deploy a validating admission controller (e.g., OPA/Gatekeeper or Kyverno) to reject Ingress resources containing the nginx.ingress.kubernetes.io/auth-method annotation. Additionally, restrict RBAC permissions so that only trusted users and service accounts can create or modify Ingress resources, and limit the ingress-nginx controller's Secret access to only the Secrets it strictly requires rather than cluster-wide access.
The vulnerability was covered by CSO Online and Network World as part of a broader report on four new ingress-nginx vulnerabilities (CSO Online). The runZero blog published a technical analysis of the Kubernetes ingress-nginx controller vulnerabilities (runZero Blog). Datadog Security Labs also published commentary in the context of ingress-nginx's broader retirement announcement (Datadog Security Labs). CISA included the vulnerability in its weekly bulletin (SB26-040), and national CERTs including CERT.at, CSA Singapore, and Belgium's CCB issued advisories. The Hacker Wire covered the RCE angle on social media and its website (The Hacker Wire).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."