CVE-2026-24514Disclosure

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 4 mentions (2026-02-03); latest day: 1
  • 8 total mentions across 4 days

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-02-02: 1Mentions · 2026-02-03: 4Mentions · 2026-02-04: 2Mentions · 2026-02-08: 1Patch / Workaround · 2026-02-04: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-04: 2Technical Details · 2026-02-08: 102-0202-0302-0402-08
Signal classification2 categories
Disclosure
562.5%
General
337.5%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-021
General1
2026-02-034
Disclosure2General2
2026-02-042
Disclosure2
2026-02-081
Disclosure1
Full discourse8 posts
  • Kubernetes@kubernetesio
    General

    CVE-2026-24514: ingress-nginx Admission Controller denial of service - https://github.com/kubernetes/kubernetes/issues/136680

    Post summary

    The entry points to CVE-2026-24514, noting a denial‑of‑service flaw in ingress‑nginx's Admission Controller and linking to a GitHub issue, but provides no further exploit or mitigation details.

    112028105.2K
    319.1K followersView on X
  • K8sContributors@K8sContributors
    Disclosure

    CVE-2026-24514: ingress-nginx Admission Controller denial of service - https://github.com/kubernetes/kubernetes/issues/136680

    Post summary

    The text announces a denial‑of‑service vulnerability (CVE‑2026‑24514) in the ingress‑nginx Admission Controller and links to a GitHub issue for further details.

    00052412
    15.9K followersView on X
  • NanoVMs@nanovms
    General

    is it appropriate to announce FOUR cves in a product that you sent a threatening note literally last week was going to be deprecated and you don't have the builds ready yet? CVE-2026-1580 CVE-2026-24512 CVE-2026-24513 CVE-2026-24514 - kubernetes is a total joke https://t.co/p76bIAk5SX

    Post summary

    The tweet merely lists four CVE identifiers with no further detail, patch information, or evidence of exploitation, offering no actionable intelligence.

    01050806
    2.0K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    Kubernetes: Multiple issues in ingress-nginx https://www.openwall.com/lists/oss-security/2026/02/02/3 Multiple issues are recently disclosed in ingress-nginx, and assigned CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514. The most serious of these issues have been rated HIGH, CVSS 8.8.

    Post summary

    Multiple high‑severity CVEs (CVE‑2026‑1580, CVE‑2026‑24512, CVE‑2026‑24513, CVE‑2026‑24514) affecting Kubernetes ingress‑nginx were recently disclosed, with a CVSS score of 8.8.

    00040437
    4.4K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24514 A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large reque… https://www.cve.org/CVERecord?id=CVE-2026-24514

    Post summary

    The post discloses a denial‑of‑service flaw in ingress‑nginx’s validating admission controller, triggered by large requests, but offers no evidence of active exploitation, patches, or PoC.

    10000139
    56.5K followersView on X
  • hi^^@collysucker
    Disclosure

    https://discuss.kubernetes.io/t/security-advisory-multiple-issues-in-ingress-nginx/34115 Multiple issues are disclosed today in ingress-nginx, assigned the following CVE IDs: CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514 This issue affects ingress-nginx. Affected ingress-nginx: < v1.13.7 & ingress-nginx: < v1.14.3 #infosec

    Post summary

    The advisory announces multiple newly disclosed CVEs (CVE-2026-1580, CVE-2026-24512, CVE-2026-24513, CVE-2026-24514) affecting ingress‑nginx versions below v1.13.7 and v1.14.3, without providing additional technical or mitigation details.

    00100209
    220 followersView on X
  • Chris Short@ChrisShort
    General

    CVE-2026-24514 #devopsish #kubernetes #cve https://github.com/kubernetes/kubernetes/issues/136680

    Post summary

    The tweet references CVE-2026-24514 with a link to a GitHub issue but provides no details on exploitation, patches, or technical specifics.

    00001120
    18.9K followersView on X
  • Checkmarx Zero@CheckmarxZero
    Disclosure

    ⏳ With EOL in March, Ingress #NGINX has 4 newly disclosed vulnerabilities: 🔴 CVE-2026-1580 and CVE-2026-24512 allow for configuration injection via the "http://nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively 🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests. ⚪ CVE-2026-24513 is a bypass of the protection afforded by the "auth-url" ingress when a misconfiguration is in place. We recommend that you migrate to F5's NGINX Ingress: https://github.com/nginx/kubernetes-ingress If you can’t migrate yet, update to v1.14.3.

    Post summary

    The post announces four new CVEs in ingress‑nginx, describing their impact and recommending a version 1.14.3 update.

    0000096
    221 followersView on X

Explore more