HIGH
ingress-nginx rewrite-target nginx configuration injection
Published Mar 9, 2026
8.8
HIGHCVSS 3.1
EPSS 0.74%
Description
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Affected products
-
- Version 0StatusaffectedConstraints<1.13.8
- Version 0StatusaffectedConstraints<1.14.4
- Version 0StatusaffectedConstraints<1.15.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Kubernetes | Ingress-Nginx | affected |
|
OR
- < 1.13.8
- ≥ 1.14.0 · < 1.14.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (4)
- http://www.openwall.com/lists/oss-security/2026/03/09/8 Mailing ListThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-10360 Advisory
- https://github.com/bvabhishek/CVE-2026-3288-lab exploitMitigationThird Party Advisory
- https://github.com/kubernetes/kubernetes/issues/137560 Issue TrackingThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/03/09/8 | Mailing ListThird Party Advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-10360 | Advisory | |
| https://github.com/bvabhishek/CVE-2026-3288-lab | exploitMitigationThird Party Advisory | |
| https://github.com/kubernetes/kubernetes/issues/137560 | Issue TrackingThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Mar 9, 2026
Updated Apr 30, 2026
Reserved Feb 26, 2026
Link CVE-2026-3288
CISA Vulnrichment
Updated Apr 30, 2026
ENISA EUVD
EUVD-2026-10360 Assigner kubernetes
Published Mar 9, 2026
Updated Apr 30, 2026
Exploited since n/a
Link EUVD-2026-10360