CVE-2026-24512Disclosure

HIGHCVSS 8.8 · HIGH

Exploitation observed; activity peaked at 5 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A security issue was discovered in ingress-nginx where the `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 26 mentions across 14 observed days

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 17 signals
  • Disclosure: 11 classified signals
  • General: 7 classified signals
  • Peaked 12d ago at 5 mentions (2026-02-03); latest day: 1
  • 26 total mentions across 14 days

Deep dive

Activity timeline26 mentions / 14d
01345Mentions · 2026-02-02: 1Mentions · 2026-02-03: 5Mentions · 2026-02-04: 5Mentions · 2026-02-05: 1Mentions · 2026-02-06: 3Mentions · 2026-02-08: 1Mentions · 2026-02-09: 1Mentions · 2026-02-12: 1Mentions · 2026-03-11: 2Mentions · 2026-03-17: 1Mentions · 2026-03-18: 2Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Mentions · 2026-08-07: 1PoC Mentioned / Linked · 2026-02-06: 1Exploit Tool / Code · 2026-02-06: 1Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-02-04: 3Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-02-03: 3Technical Details · 2026-02-04: 4Technical Details · 2026-02-06: 1Technical Details · 2026-02-08: 1Technical Details · 2026-02-09: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-17: 1Technical Details · 2026-03-18: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 1Technical Details · 2026-08-07: 102-0202-0302-0402-0502-0602-0802-0902-1203-1103-1703-1804-1404-1908-07
Signal classification5 categories
Disclosure
1142.3%
General
726.9%
Patch
623.1%
PoC
13.8%
Active Exploitation
13.8%
Referenced assets17 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-035
Disclosure3General2
2026-02-045
Disclosure1General1Patch3
2026-02-051
General1
2026-02-063
Disclosure1General1PoC1
2026-02-081
Disclosure1
2026-02-091
Patch1
2026-02-121
Disclosure1
2026-03-112
Active Exploitation1Disclosure1
2026-03-171
Disclosure1
2026-03-182
Disclosure1General1
2026-04-141
Patch1
2026-04-191
Disclosure1
2026-08-071
Patch1
Full discourse20 posts
  • Kubernetes@kubernetesio
    Disclosure

    CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/136678

    Post summary

    The post references CVE-2026-24512, describing an ingress‑nginx configuration injection flaw and points to a GitHub issue for further details.

    18055137.2K
    319.1K followersView on X
  • Olivier Poncet 🦝@ponceto91
    General

    Le monde Kubernetes/ingress-nginx en sueurs ... Grosse vulnérabilité découverte : CVE-2026-24512 https://cyberpress.org/ingress-nginx-vulnerability-allows-attackers-to-execute-arbitrary-code/

    Post summary

    A new Kubernetes/ingress-nginx vulnerability (CVE-2026-24512) is reported, but the brief excerpt offers no detailed technical information or evidence of exploitation.

    612032206.3K
    15.3K followersView on X
  • Sysdig@sysdig
    Disclosure

    🚨 Kubernetes alert: ingress-nginx vulnerabilities could lead to config injection and potential RCE. Sysdig Threat Research analyzed: • CVE-2026-3288 (CVSS 8.8) • CVE-2026-24512 Missing input sanitization lets attackers inject nginx directives via Ingress paths. Impact: RCE, secret exposure, traffic hijacking. Full analysis ↓ http://www.sysdig.com/blog/detecting-cve-2026-3288-cve-2026-24512-ingress-nginx-configuration-injection-vulnerabilities-for-kubernetes

    Post summary

    Sysdig’s blog discloses that CVE‑2026‑3288 and CVE‑2026‑24512 allow attackers to inject nginx directives via Ingress paths, leading to potential RCE on Kubernetes clusters; no PoC or active exploitation is reported.

    03072297
    10.2K followersView on X
  • K8sContributors@K8sContributors
    General

    CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/136678

    Post summary

    CVE-2026-24512 is identified as a configuration injection flaw in ingress-nginx, but the provided text lacks evidence of PoC, exploit code, active attacks, or mitigation steps.

    01053385
    15.9K followersView on X
  • NanoVMs@nanovms
    General

    is it appropriate to announce FOUR cves in a product that you sent a threatening note literally last week was going to be deprecated and you don't have the builds ready yet? CVE-2026-1580 CVE-2026-24512 CVE-2026-24513 CVE-2026-24514 - kubernetes is a total joke https://t.co/p76bIAk5SX

    Post summary

    The tweet merely lists four CVE identifiers and criticizes Kubernetes, providing no technical details, PoCs, exploits, patches, or evidence of active exploitation.

    01050806
    2.0K followersView on X
  • Maxime Escourbiac@Fisjkars
    PoC

    We were acknowledged for CVE-2026-24512 vulnerability (8.8) on Nginx-Ingress controller with @cousky_. H1 report disclosure is on-going. It ended up being a pretty funny Lua script restriction bypass. #security #k8s

    Post summary

    The tweet announces CVE-2026-24512 on Nginx‑Ingress with a Lua script bypass PoC; no patch or active exploitation is reported.

    01040178
    262 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Ingress-NGINX の脆弱性 CVE-2026-24512 が FIX:任意のコード実行の恐れ https://iototsecnews.jp/2026/02/04/ingress-nginx-vulnerability-allow-attackers-to-execute-arbitrary-code/ この問題の原因は、Kubernetes のネットワークの入り口を管理する Ingress-NGINX において、設定項目の一部 (pathフィールド) に入力された内容のチェックが不十分だったことにあります。この不備がある状態で、攻撃者が特定の細工を施した設定 (Ingressリソース) を登録すると、本来は安全に保たれるべきサーバの設定ファイルの中に、悪意のある命令を紛れ込ませることが可能になります。この原因により、攻撃者はサーバ上でのプログラム実行や、クラスター内に保管されている機密情報の窃取が可能になります。ご利用のチームは、ご注意ください。 #CVE202624512 #nginx #Vulnerability

    Post summary

    The article reports that CVE-2026-24512 in Ingress‑NGINX permits attackers to inject malicious commands via the path field, leading to arbitrary code execution, but offers no information on patches, exploits, or active use.

    01102209
    483 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Kubernetes: Multiple issues in ingress-nginx https://www.openwall.com/lists/oss-security/2026/02/02/3 Multiple issues are recently disclosed in ingress-nginx, and assigned CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514. The most serious of these issues have been rated HIGH, CVSS 8.8.

    Post summary

    Several CVEs (CVE-2026-1580, 2026-24512, 2026-24513, 2026-24514) have been disclosed for ingress-nginx with high severity (CVSS 8.8), but no PoC, exploit, or patch information is provided.

    00040437
    4.4K followersView on X
  • GOMOOT@grazymen
    General

    💡 CVE-2026-24512: la vulnerabilità di ingress-NGINX che minaccia i cluster Kubernetes https://gomoot.com/cve-2026-24512-la-vulnerabilita-di-ingress-nginx-che-minaccia-i-cluster-kubernetes/ #news #sicurezza #tech https://t.co/X0b6imSzrT

    Post summary

    A tweet linking to a news article about CVE‑2026‑24512, a Kubernetes cluster vulnerability, without providing additional details.

    0002179
    2.2K followersView on X
  • Wasteland@wastelandweekly
    Active Exploitation

    🚨 CVE-2026-24512 — CVE-2026-24512. Actively exploited in the wild. Thread 👇

    Post summary

    The tweet confirms that CVE-2026-24512 is being actively exploited in the wild, with a reference to a thread for additional context.

    1001023
    6 followersView on X
  • Chris Short@ChrisShort
    General

    CVE-2026-24512 #devopsish #kubernetes #cve https://github.com/kubernetes/kubernetes/issues/136678

    Post summary

    The post references CVE-2026-24512 and links to a GitHub issue, but provides no further information about the vulnerability or its exploitation.

    01010145
    18.9K followersView on X
  • Lane Williams@lanew44
    Disclosure

    🚨 New from Sysdig Threat Research Team: 2 ingress-nginx vulnerabilities (CVE-2026-3288, CVE-2026-24512) could allow configuration injection and potential RCE in K8s Root cause: missing input sanitization in Ingress path translation Deep dive & guidance https://okt.to/nzs3GE https://t.co/dX2JmxzTCy

    Post summary

    Sysdig’s Threat Research Team announces two ingress‑nginx CVEs (CVE‑2026‑3288, CVE‑2026‑24512) that allow configuration injection and potential RCE due to missing input sanitization.

    0000149
    6 followersView on X
  • Wasteland@wastelandweekly
    Disclosure

    What it is: CVE-2026-24512 is classified as a security issue within the ingress-nginx component. The root cause involves improper input validation (CWE-20) where the `rules.http.paths.path` Ingress field can be exploited to inject configuration directly into nginx. This flaw was…

    Post summary

    The text announces CVE-2026-24512 as a security issue in ingress-nginx, describing improper input validation that could lead to configuration injection, but it lacks details on PoC, exploits, active use, or remediation.

    1000028
    6 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: #Kubernetes disclosed four vulnerabilities in the #ingress-nginx, including two high-severity issues: #CVE-2026-1580 (improper input validation) and #CVE-2026-24512 (configuration injection), enabling #RCE and authentication bypass. https://ccb.belgium.be/advisories/warning-multiple-vulnerabilities-kubernetes-ingres-nginx #Patch

    Post summary

    The advisory announces four high‑severity vulnerabilities in ingress‑nginx, including RCE and authentication bypass, and confirms that patches are available.

    01000255
    7.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en Ingress-NGINX ❗ CVE-2026-24512 ❗ CVE-2026-1580 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-ingress-nginx/ https://t.co/TrYFac4pTk

    Post summary

    The tweet announces two CVEs affecting Ingress‑NGINX and directs readers to external links for details, but provides no evidence of exploitation, PoC, or mitigation.

    00001144
    6.6K followersView on X
  • Cristina Imbucatura@Imbucatura72
    General

    CVE-2026-24512: la vulnerabilità di ingress-NGINX che minaccia i cluster Kubernetes https://gomoot.com/cve-2026-24512-la-vulnerabilita-di-ingress-nginx-che-minaccia-i-cluster-kubernetes/ #news #sicurezza #tech https://t.co/QnZBrg9NEu

    Post summary

    The tweet mentions CVE‑2026‑24512, a vulnerability in ingress‑NGINX that threatens Kubernetes clusters, but it offers no technical details, PoC, or patch information.

    0001060
    20 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24512 A security issue was discovered in ingress-nginx cthe `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary… https://www.cve.org/CVERecord?id=CVE-2026-24512

    Post summary

    A configuration‑injection vulnerability was identified in ingress‑nginx that allows arbitrary configuration changes in nginx via the `rules.http.paths.path` field.

    10000156
    56.5K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-24512: HIGH] Ingress-nginx security alert: Exploitable vulnerability found in `rules.http.paths.path` field, allowing potential code execution and disclosure of Secrets. Upgrade recommended.#cve,CVE-2026-24512,#cybersecurity https://cvefind.com/CVE-2026-24512

    Post summary

    A high‑severity alert for CVE‑2026‑24512 identifies a potential code execution flaw in Ingress‑nginx, recommending an upgrade to mitigate the risk.

    00010105
    583 followersView on X
  • hi^^@collysucker
    Disclosure

    https://discuss.kubernetes.io/t/security-advisory-multiple-issues-in-ingress-nginx/34115 Multiple issues are disclosed today in ingress-nginx, assigned the following CVE IDs: CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514 This issue affects ingress-nginx. Affected ingress-nginx: < v1.13.7 & ingress-nginx: < v1.14.3 #infosec

    Post summary

    The post is a security advisory that announces several CVEs affecting older ingress‑nginx releases, but it contains no further technical detail or mitigation information.

    00100209
    220 followersView on X
  • motch | ソフトウェアエンジニア👨‍💻@motch_dev
    Disclosure

    🔗 CVE-2026-24512: ingress-nginx rules.http.paths.path nginx configuration injection https://github.com/kubernetes/kubernetes/issues/136678

    Post summary

    A new CVE (CVE-2026-24512) concerning ingress-nginx configuration injection is cited via a GitHub issue, with no PoC, exploit, or patch details provided.

    0001074
    254 followersView on X

Explore more