Back

HIGH

ingress-nginx rewrite-target nginx configuration injection

Published Mar 9, 2026

Description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner kubernetes
Published Mar 9, 2026
Updated Apr 30, 2026
Reserved Feb 26, 2026
CISA Vulnrichment
Updated Apr 30, 2026
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner kubernetes
Published Mar 9, 2026
Updated Apr 30, 2026
Exploited since n/a
EUVD-2026-10360