CVE-2026-3288Disclosure(kubernetes / ingress-nginx)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kubernetes ingress-nginx systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ingress-nginx

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 21 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 19 signals
  • Disclosure: 14 classified signals
  • General: 2 classified signals
  • Peaked 11d ago at 6 mentions (2026-03-09); latest day: 1
  • 21 total mentions across 12 days

Affected systems

Vendors
Products
ingress-nginx

Deep dive

Activity timeline21 mentions / 12d
02356Mentions · 2026-03-09: 6Mentions · 2026-03-10: 2Mentions · 2026-03-12: 1Mentions · 2026-03-13: 1Mentions · 2026-03-17: 2Mentions · 2026-03-18: 2Mentions · 2026-03-19: 1Mentions · 2026-04-08: 1Mentions · 2026-04-14: 1Mentions · 2026-04-19: 1Mentions · 2026-07-02: 2Mentions · 2026-08-12: 1PoC Mentioned / Linked · 2026-03-09: 1PoC Mentioned / Linked · 2026-03-19: 1PoC Mentioned / Linked · 2026-04-08: 1Exploit Tool / Code · 2026-03-19: 1Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-17: 1Patch / Workaround · 2026-04-14: 1Technical Details · 2026-03-09: 5Technical Details · 2026-03-10: 2Technical Details · 2026-03-13: 1Technical Details · 2026-03-17: 2Technical Details · 2026-03-18: 2Technical Details · 2026-03-19: 1Technical Details · 2026-04-08: 1Technical Details · 2026-04-14: 1Technical Details · 2026-04-19: 1Technical Details · 2026-07-02: 2Technical Details · 2026-08-12: 103-0903-1003-1203-1303-1703-1803-1904-0804-1404-1907-0208-12
Signal classification5 categories
Disclosure
1466.7%
Patch
314.3%
General
29.5%
Exploit
14.8%
PoC
14.8%
Referenced assets21 URLs
Classification over time
DateTotalLabels
2026-03-096
Disclosure5General1
2026-03-102
Disclosure1Patch1
2026-03-121
Disclosure1
2026-03-131
Disclosure1
2026-03-172
Disclosure1Patch1
2026-03-182
Disclosure1General1
2026-03-191
Exploit1
2026-04-081
PoC1
2026-04-141
Patch1
2026-04-191
Disclosure1
2026-07-022
Disclosure2
2026-08-121
Disclosure1
Full discourse20 posts
  • Kubernetes@kubernetesio
    Disclosure

    CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/137560

    Post summary

    The snippet announces CVE‑2026‑3288, a configuration injection vulnerability in ingress‑nginx, and links to a GitHub issue for further details.

    3100321316.4K
    326.3K followersView on X
  • Sysdig@sysdig
    Disclosure

    🚨 Kubernetes alert: ingress-nginx vulnerabilities could lead to config injection and potential RCE. Sysdig Threat Research analyzed: • CVE-2026-3288 (CVSS 8.8) • CVE-2026-24512 Missing input sanitization lets attackers inject nginx directives via Ingress paths. Impact: RCE, secret exposure, traffic hijacking. Full analysis ↓ http://www.sysdig.com/blog/detecting-cve-2026-3288-cve-2026-24512-ingress-nginx-configuration-injection-vulnerabilities-for-kubernetes

    Post summary

    Sysdig Threat Research reports two Kubernetes ingress-nginx vulnerabilities (CVE‑2026‑3288 and CVE‑2026‑24512) that allow configuration injection leading to remote code execution, highlighting potential impact but no active exploitation or PoC evidence.

    03072297
    10.2K followersView on X
  • dbugs@ptdbugs
    Disclosure

    ingress-nginx rewrite-target nginx configuration injection CVE: CVE-2026-3288 PT-Identifier: PT-2026-24119 Vendor: Kubernetes Product: ingress-nginx CVSS: 8.8 Credits: Kai Aizen Description: A security issue was discovered in ingress-nginx where the "http://nginx.ingress.kubernetes.io/rewrite-target" Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.) References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-3288 • https://github.com/kubernetes/kubernetes/issues/137560 #dbugs_vuln

    Post summary

    A disclosed CVE (CVE-2026-3288) for ingress-nginx allows injection via the rewrite-target annotation, causing potential code execution and secrets leakage, with no exploit or patch details provided.

    01054612
    554 followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-3288: Kubernetes: ingress-nginx rewrite-target nginx configuration injection https://www.openwall.com/lists/oss-security/2026/03/09/8 can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. CVSS 8.8.

    Post summary

    The text announces CVE-2026‑3288, a Kubernetes ingress‑nginx configuration injection that can result in arbitrary code execution and Secrets disclosure, providing a link to an openwall mailing‑list discussion and a CVSS score of 8.8.

    010521.1K
    4.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A high 8.8 CVSS flaw (CVE-2026-3288) in ingress-nginx allows arbitrary code execution and massive Kubernetes secret leakage. Patch immediately #Kubernetes #CVE #ingressnginx #CyberSecurity #InfoSec #ContainerSecurity #K8s #Vulnerability #PatchAlert #AppSec https://securityonline.info/kubernetes-security-alert-ingress-nginx-injection-flaw-risks-cluster-wide-secret-exposure/ https://t.co/c6BxfR9XcU

    Post summary

    CVE‑2026‑3288 is a high‑severity ingress‑nginx flaw enabling arbitrary code execution and secret leakage; a patch is urgently recommended.

    02040472
    10.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    CVE-2026-3288 in ingress-nginx allows config injection via double-quote in Ingress paths, enabling RCE and secret disclosure. Fix merged March 9, 2026; detection rules available from Sysdig TRT. #KubernetesSecurity #NGINXIngress #USA https://ift.tt/cYi4rnB

    Post summary

    The post announces CVE‑2026‑3288 in ingress‑nginx, details a config-injection RCE flaw, and notes that a fix was merged on March 9, 2026, with detection rules available from Sysdig TRT.

    02010166
    3.7K followersView on X
  • Chris Short@ChrisShort
    Disclosure

    [Security Advisory] CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection #devopsish https://groups.google.com/a/kubernetes.io/g/dev/c/NoW4Ollgoxc/m/m1to2nAqAAAJ?utm_medium=email&utm_source=footer

    Post summary

    A security advisory announces CVE-2026-3288, detailing an ingress-nginx rewrite-target configuration injection vulnerability.

    00021261
    18.9K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-3288 Vendor: Kubernetes Product: ingress-nginx Description: A security issue was discovered in ingress-nginx where the "http://nginx.ingress.kubernetes.io/rewrite-target" Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.) Link: https://github.com/bvabhishek/CVE-2026-3288-lab #dbugs_vuln

    Post summary

    A PoC/exploit for CVE‑2026‑3288 in ingress‑nginx has been released, demonstrating arbitrary code execution via the rewrite‑target annotation, with source code available on GitHub.

    00002314
    788 followersView on X
  • Lane Williams@lanew44
    Disclosure

    🚨 New from Sysdig Threat Research Team: 2 ingress-nginx vulnerabilities (CVE-2026-3288, CVE-2026-24512) could allow configuration injection and potential RCE in K8s Root cause: missing input sanitization in Ingress path translation Deep dive & guidance https://okt.to/nzs3GE https://t.co/dX2JmxzTCy

    Post summary

    Sysdig’s Threat Research Team announced two new ingress‑nginx CVEs that could lead to configuration injection and remote code execution due to missing input sanitization. No PoC, exploit, or patch details are provided.

    0000149
    6 followersView on X
  • CCB Alert@CCBalert
    Disclosure

    Warning: High Vulnerability in #ingress-nginx #Kubernetes. CVE-2026-3288 CVSS: 8.8. This vulnerability can lead arbitrary code execution in the context of the ingress-nginx-controller. #Patch #Patch #Patch

    Post summary

    The tweet alerts to CVE‑2026‑3288 as a high‑severity vulnerability capable of arbitrary code execution in ingress‑nginx, but does not provide PoC, exploit, active‑usage, or patch information.

    01000342
    7.2K followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en Ingress-NGINX ❗ CVE-2026-3288 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-ingress-nginx/ https://t.co/eZkzDMm3sU

    Post summary

    A new CVE—CVE-2026-3288—has been reported for Ingress-NGINX, with more information available via external links provided in the text.

    00001122
    6.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-3288 Kubernetes Ingress-Nginx Vulnerability Enables Arbitrary Code Exec... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3288 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely lists CVE-2026-3288 and links to a vulnerability page, without providing PoC, exploitation details, patches, or technical information.

    0000174
    4.0K followersView on X
  • Donweb Media@DonwebMedia
    Disclosure

    Si usás ingress-nginx: dos CVE (CVSS 8.8) que permiten RCE y robo de Secrets desde un Ingress. El timing es lo mejor: justo cuando el proyecto se despide 🔒 https://cloud.donweb.com/ingress-nginx-cve-2026-3288-y-4342-inyeccion-y-fin-de-vida/ #Ciberseguridad #Kubernetes

    Post summary

    The message announces two CVE‑identified vulnerabilities in ingress-nginx with CVSS 8.8 that allow RCE and secret theft, without mention of PoC, exploit code, patch, or active exploitation.

    0000058
    6 followersView on X
  • K8sContributors@K8sContributors
    Disclosure

    CVE-2026-3288: ingress-nginx rewrite-target nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/137560

    Post summary

    A new nginx configuration injection vulnerability (CVE-2026-3288) affecting ingress-nginx’s rewrite‑target logic has been disclosed, with details linked to a GitHub issue.

    00000573
    16.5K followersView on X
  • Lane Williams@lanew44
    Patch

    CVE-2026-3288 — Kubernetes users: ▸ What: NGINX Ingress Controller path field injection via " ▸ Affected: ingress-nginx < v1.13.8, v1.14.4, v1.15.0 ▸ Impact: RCE, secret theft, response hijack, redirect ▸ Fix: Upgrade to v1.13.8 / v1.14.4 / v1.15.0 ▸ Urgency: High — patch now

    Post summary

    The advisory identifies a path field injection flaw in NGINX Ingress Controller that enables remote code execution and other attacks, and it recommends upgrading to the patched versions immediately.

    0000041
    6 followersView on X
  • litios@liti0s
    Exploit

    A while ago, I developed an exploit for IngressNightmare https://github.com/litios/xpls/tree/main/ingressnightmare Recently, I took a look at CVE-2026-3288, a variation of IngressNightmare that also revolves around injection and pwned it by enhancing my old approach. https://litios.github.io/2026/03/19/reliving-the-nightmare.html

    Post summary

    The author shares an updated exploit, hosted on GitHub, for CVE-2026-3288—an injection-based vulnerability—and claims successful exploitation of the variant.

    0000068
    46 followersView on X
  • Emanuela Zaccone@Zatomas
    Disclosure

    🚨 New from Sysdig Threat Research Team: 2 ingress-nginx vulnerabilities (CVE-2026-3288, CVE-2026-24512) could allow configuration injection and potential RCE in K8s Root cause: missing input sanitization in Ingress path translation Deep dive &amp; guidance https://okt.to/jS8MhW https://t.co/CUJ0Hfux8w

    Post summary

    Sysdig’s Threat Research Team alerts on two new ingress-nginx CVEs that allow configuration injection and potential RCE in Kubernetes, attributing the flaw to missing input sanitization during Ingress path translation.

    0000074
    14.5K followersView on X
  • Sysdig: Takao Shimizu@TakaoShimizu1
    General

    『CVE-2026-3288 と CVE-2026-24512 の検知:Kubernetes の Ingress-Nginx 構成インジェクションの脆弱性』 https://www.sysdig.com/jp/blog/detecting-cve-2026-3288-cve-2026-24512-ingress-nginx-configuration-injection-vulnerabilities-for-kubernetes #脆弱性 #IngressNginx #Falco #リアルタイム #脅威検知 #Sysdig

    Post summary

    Sysdig announces detection of two recent Ingress‑Nginx configuration injection vulnerabilities (CVE‑2026‑3288 and CVE‑2026‑24512) without providing PoC, exploit code, or patch details.

    0000077
    48 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3288: HIGH] Critical security vulnerability found in ingress-nginx! Exploiting `http://nginx.ingress.kubernetes.io/rewrite-target` can allow arbitrary code execution and Secrets disclosure to the controller.#cve,CVE-2026-3288,#cybersecurity https://cvefind.com/CVE-2026-3288

    Post summary

    A new critical CVE for ingress-nginx has been disclosed, highlighting vulnerabilities in the rewrite‑target header that enable remote code execution and secret disclosure, with no patch or PoC code provided.

    0000073
    600 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-3288 A security issue was discovered in ingress-nginx where the `http://nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into ngin… https://www.cve.org/CVERecord?id=CVE-2026-3288

    Post summary

    The text announces a new CVE (CVE‑2026‑3288) affecting ingress‑nginx, describing how the rewrite‑target annotation can be abused for configuration injection.

    0000086
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appkubernetesingress-nginx---

Explore more