CVE-2026-24513General

LOWCVSS 3.1 · LOW

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails. Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-754

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • General: 4 classified signals
  • Disclosure: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-03); latest day: 1
  • 9 total mentions across 4 days

Deep dive

Activity timeline9 mentions / 4d
01234Mentions · 2026-02-02: 1Mentions · 2026-02-03: 4Mentions · 2026-02-04: 3Mentions · 2026-02-08: 1PoC Mentioned / Linked · 2026-02-04: 1Patch / Workaround · 2026-02-04: 2Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 2Technical Details · 2026-02-08: 102-0202-0302-0402-08
Signal classification3 categories
General
444.4%
Disclosure
333.3%
Patch
222.2%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-034
Disclosure2General2
2026-02-043
General1Patch2
2026-02-081
Disclosure1
Full discourse9 posts
  • Kubernetes@kubernetesio
    Disclosure

    CVE-2026-24513: ingress-nginx auth-url protection bypass - https://github.com/kubernetes/kubernetes/issues/136679

    Post summary

    CVE-2026-24513 identifies an auth-url protection bypass in ingress-nginx, referenced through a Kubernetes GitHub issue, indicating a newly disclosed vulnerability.

    2302554.2K
    319.1K followersView on X
  • K8sContributors@K8sContributors
    General

    CVE-2026-24513: ingress-nginx auth-url protection bypass - https://github.com/kubernetes/kubernetes/issues/136679

    Post summary

    A GitHub issue references CVE-2026-24513, noting an auth-url protection bypass in ingress-nginx, but no further details such as PoC, patch, or exploitation status are provided.

    00061439
    15.9K followersView on X
  • NanoVMs@nanovms
    General

    is it appropriate to announce FOUR cves in a product that you sent a threatening note literally last week was going to be deprecated and you don't have the builds ready yet? CVE-2026-1580 CVE-2026-24512 CVE-2026-24513 CVE-2026-24514 - kubernetes is a total joke https://t.co/p76bIAk5SX

    Post summary

    The tweet lists four CVEs but offers no technical details, exploitation evidence, or patch information, merely expressing criticism.

    01050806
    2.0K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Kubernetes: Multiple issues in ingress-nginx https://www.openwall.com/lists/oss-security/2026/02/02/3 Multiple issues are recently disclosed in ingress-nginx, and assigned CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514. The most serious of these issues have been rated HIGH, CVSS 8.8.

    Post summary

    Several new CVEs for ingress‑nginx have been disclosed with high severity; no PoC, exploit, or patch information is provided.

    00040437
    4.4K followersView on X
  • Chris Short@ChrisShort
    General

    CVE-2026-24513 #devopsish #kubernetes #cve https://github.com/kubernetes/kubernetes/issues/136679

    Post summary

    The tweet merely references CVE-2026-24513 and links to a GitHub issue without providing additional details.

    01010134
    18.9K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-24513 A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific… https://www.cve.org/CVERecord?id=CVE-2026-24513

    Post summary

    The text briefly notes CVE-2026-24513 in ingress‑nginx, indicating that the auth‑url annotation protection may not be effective, and links to the CVE record, but offers no further technical or exploitation details.

    10000148
    56.5K followersView on X
  • hi^^@collysucker
    Disclosure

    https://discuss.kubernetes.io/t/security-advisory-multiple-issues-in-ingress-nginx/34115 Multiple issues are disclosed today in ingress-nginx, assigned the following CVE IDs: CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514 This issue affects ingress-nginx. Affected ingress-nginx: < v1.13.7 & ingress-nginx: < v1.14.3 #infosec

    Post summary

    A security advisory disclosed multiple CVEs affecting ingress-nginx versions below 1.13.7 and 1.14.3, with no exploitation details or patches mentioned.

    00100209
    220 followersView on X
  • Checkmarx Zero@CheckmarxZero
    Patch

    ⏳ With EOL in March, Ingress #NGINX has 4 newly disclosed vulnerabilities: 🔴 CVE-2026-1580 and CVE-2026-24512 allow for configuration injection via the "http://nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively 🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests. ⚪ CVE-2026-24513 is a bypass of the protection afforded by the "auth-url" ingress when a misconfiguration is in place. We recommend that you migrate to F5's NGINX Ingress: https://github.com/nginx/kubernetes-ingress If you can’t migrate yet, update to v1.14.3.

    Post summary

    Four new Ingress‑NGINX CVEs are disclosed, with technical details on configuration injection, DoS, and auth bypass, and the post recommends updating to v1.14.3 or migrating to F5’s NGINX Ingress.

    0000096
    221 followersView on X
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2026-24513: Authentication Bypass Alert 🚨 Kubernetes ingress-nginx An authentication bypass vulnerability has been disclosed in ingress-nginx, allowing unauthenticated access only under highly specific non-default configurations involving external authentication and custom error backends. Risk Severity: Medium–High (Contextual), limited exposure, no active exploitation observed, public proof-of-concept available Impact: Unauthenticated access to protected Kubernetes services Bypass of auth-url external authentication enforcement Exposure of internal APIs and sensitive application endpoints Root Cause: CWE-757 — Improper trust in HTTP responses from an external custom error backend ingress-nginx relies on the X-Code header to preserve 401/403 auth failures A defective external backend returning HTTP 200 causes ingress-nginx to incorrectly grant access Attackers can: Target ingress resources using auth-url + custom-http-errors Abuse misbehaving external error backends that ignore X-Code headers Bypass authentication controls without valid credentials Are You Affected? Vulnerable: ingress-nginx deployments with External authentication enabled custom-http-errors routed to an external backend Backend incorrectly converting 401/403 into HTTP 200 Not affected: Default ingress-nginx configurations using the built-in error backend Immediate Action Required: Update: Upgrade to ingress-nginx v1.11.4, v1.12.1, or later Audit: Identify Ingress objects using both auth-url and custom-http-errors annotations Mitigation: Replace external error backends or fix X-Code header handling Detect: Monitor for HTTP 200 responses with auth_response_status=401/403 in ingress-nginx logs Misconfigured error paths can silently kill authentication. Fix before attackers notice. 🛡️ #ostorlabCVE

    Post summary

    CVE‑2026‑24513 is an authentication bypass in ingress‑nginx that permits unauthenticated access under specific external authentication setups. A public PoC exists, no active exploitation has been observed, and users are advised to upgrade to the latest versions and audit their configurations.

    0000077
    582 followersView on X

Explore more