CVE-2026-1580Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 15 mentions across 8 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 9 signals
  • Disclosure: 11 classified signals
  • General: 1 classified signal
  • Peaked 6d ago at 5 mentions (2026-02-03); latest day: 2
  • 15 total mentions across 8 days

Deep dive

Activity timeline15 mentions / 8d
01345Mentions · 2026-02-02: 1Mentions · 2026-02-03: 5Mentions · 2026-02-04: 3Mentions · 2026-02-06: 1Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-17: 1Mentions · 2026-10-06: 2Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-17: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 3Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-17: 102-0202-0302-0402-0602-0802-0902-1710-06
Signal classification3 categories
Disclosure
1184.6%
General
17.7%
Patch
17.7%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-035
Disclosure5
2026-02-043
Disclosure3
2026-02-061
Disclosure1
2026-02-081
Disclosure1
2026-02-091
Disclosure1
2026-02-171
Patch1
Full discourse15 posts
  • Kubernetes@kubernetesio
    Disclosure

    CVE-2026-1580: ingress-nginx auth-method nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/136677

    Post summary

    The text announces the discovery of CVE‑2026‑1580, detailing a configuration injection flaw in ingress‑nginx, but does not provide a PoC, exploit code, patch, or evidence of active exploitation.

    010251159.4K
    319.1K followersView on X
  • NanoVMs@nanovms
    General

    is it appropriate to announce FOUR cves in a product that you sent a threatening note literally last week was going to be deprecated and you don't have the builds ready yet? CVE-2026-1580 CVE-2026-24512 CVE-2026-24513 CVE-2026-24514 - kubernetes is a total joke https://t.co/p76bIAk5SX

    Post summary

    The tweet references four Kubernetes CVEs but offers no technical details, exploitation evidence, or mitigation information, merely expressing frustration.

    01050806
    2.0K followersView on X
  • K8sContributors@K8sContributors
    Disclosure

    CVE-2026-1580: ingress-nginx auth-method nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/136677

    Post summary

    CVE-2026-1580 is a configuration injection vulnerability in ingress-nginx auth-method, with details linked to a GitHub issue.

    02030541
    15.9K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Kubernetes: Multiple issues in ingress-nginx https://www.openwall.com/lists/oss-security/2026/02/02/3 Multiple issues are recently disclosed in ingress-nginx, and assigned CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514. The most serious of these issues have been rated HIGH, CVSS 8.8.

    Post summary

    Several CVEs have been disclosed for ingress‑nginx, with the most serious rated HIGH and a CVSS score of 8.8.

    00040437
    4.4K followersView on X
  • CVE Brief@DailyCVEBrief

    LOOK BACK: In 2023, ingress-nginx hardened its annotations. One check went from an exact list of HTTP verbs to a regex with no ^ or $, so "GET" plus nginx directives passed. CVE-2026-1580 turned that into code execution and cluster-wide Secret access. https://t.co/O5OmAm9Dz1

    1000048
    34 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: #Kubernetes disclosed four vulnerabilities in the #ingress-nginx, including two high-severity issues: #CVE-2026-1580 (improper input validation) and #CVE-2026-24512 (configuration injection), enabling #RCE and authentication bypass. https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-kubernetes-ingres-nginx #Patch

    Post summary

    Kubernetes announced four ingress‑nginx vulnerabilities, including CVE‑2026‑1580 and CVE‑2026‑24512, that enable RCE and authentication bypass, with a patch advisory available.

    01000255
    7.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en Ingress-NGINX ❗ CVE-2026-24512 ❗ CVE-2026-1580 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-ingress-nginx/ https://t.co/TrYFac4pTk

    Post summary

    The tweet announces two CVEs (CVE‑2026‑24512 and CVE‑2026‑1580) affecting Ingress‑NGINX and points to external links for further information.

    00001144
    6.6K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1580 A security issue was discovered in ingress-nginx where the `http://nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. … https://www.cve.org/CVERecord?id=CVE-2026-1580

    Post summary

    A new vulnerability in ingress-nginx allows configuration injection via the auth-method annotation. No PoC, exploit code, or patch details are provided.

    10000163
    56.5K followersView on X
  • hi^^@collysucker
    Disclosure

    https://discuss.kubernetes.io/t/security-advisory-multiple-issues-in-ingress-nginx/34115 Multiple issues are disclosed today in ingress-nginx, assigned the following CVE IDs: CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514 This issue affects ingress-nginx. Affected ingress-nginx: < v1.13.7 & ingress-nginx: < v1.14.3 #infosec

    Post summary

    The advisory announces the discovery of multiple new CVEs affecting ingress-nginx, specifying the vulnerable versions but providing no further technical details or mitigation guidance.

    00100209
    220 followersView on X
  • Kubernetes with Naveen 🇮🇳@NaveenS16
    Disclosure

    Security Alert for #Kubernetes users! L CVE-2026-1580 is a High-rated (8.8) injection flaw in ingress-nginx. An attacker with Ingress creation permissions can bypass validation to inject arbitrary Nginx config and steal controller credentials

    Post summary

    A high‑rated injection flaw (CVE‑2026‑1580) in ingress‑nginx allows attackers with Ingress creation permissions to bypass validation, inject arbitrary Nginx configuration, and steal controller credentials.

    10000212
    10.7K followersView on X
  • CVE Brief@DailyCVEBrief

    Full Look Back writeup: the 2016 check, the 2023 rewrite, why it was rated low risk, and what retirement means for the next bug: https://cvebrief.com/cve/cve-2026-1580/ https://t.co/zAh0CxsiEI

    0000030
    34 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    CVE-2026-1580: `nginx-ingress-controller` is vulnerable to auth-method configuration injection. Upgrade to 1.14.2+ to mitigate this #Kubernetes #infosec issue. https://www.pulsepatch.io/posts/cve-2026-1580-nginx-ingress-controller-config-injection

    Post summary

    CVE‑2026‑1580 enables auth‑method configuration injection in nginx‑ingress‑controller; updating to 1.14.2 or later mitigates the vulnerability.

    0000058
    1 followersView on X
  • Checkmarx Zero@CheckmarxZero
    Disclosure

    ⏳ With EOL in March, Ingress #NGINX has 4 newly disclosed vulnerabilities: 🔴 CVE-2026-1580 and CVE-2026-24512 allow for configuration injection via the "http://nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively 🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests. ⚪ CVE-2026-24513 is a bypass of the protection afforded by the "auth-url" ingress when a misconfiguration is in place. We recommend that you migrate to F5's NGINX Ingress: https://github.com/nginx/kubernetes-ingress If you can’t migrate yet, update to v1.14.3.

    Post summary

    The message discloses four new NGINX Ingress CVEs, explains their impacts, and recommends updating to version 1.14.3 or migrating to F5’s NGINX Ingress as a mitigation.

    0000096
    221 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-1580: HIGH] Security flaw in ingress-nginx allows injection of code via `auth-method` annotation, leading to code execution & Secret exposure. Ensure protection against cyber threats.#cve,CVE-2026-1580,#cybersecurity https://cvefind.com/CVE-2026-1580

    Post summary

    The post announces a high‑severity vulnerability (CVE‑2026‑1580) in ingress‑nginx that permits code injection through the `auth-method` annotation, enabling code execution and secret exposure.

    0000097
    583 followersView on X
  • Chris Short@ChrisShort
    Disclosure

    CVE-2026-1580 #devopsish #kubernetes #cve https://github.com/kubernetes/kubernetes/issues/136677

    Post summary

    The text references CVE-2026-1580 and links to a GitHub issue, indicating a discussion or initial disclosure without further details.

    00000130
    18.9K followersView on X

Explore more