Kubernetes[verified]@kubernetesioDisclosure
The snippet announces CVE‑2026‑3288, a configuration injection vulnerability in ingress‑nginx, and links to a GitHub issue for further details.
Sysdig[verified]@sysdigDisclosure
Sysdig Threat Research reports two Kubernetes ingress-nginx vulnerabilities (CVE‑2026‑3288 and CVE‑2026‑24512) that allow configuration injection leading to remote code execution, highlighting potential impact but no active exploitation or PoC evidence.
dbugs[verified]@ptdbugsDisclosure
A disclosed CVE (CVE-2026-3288) for ingress-nginx allows injection via the rewrite-target annotation, causing potential code execution and secrets leakage, with no exploit or patch details provided.
dbugs[verified]@ptdbugsPoC
A PoC/exploit for CVE‑2026‑3288 in ingress‑nginx has been released, demonstrating arbitrary code execution via the rewrite‑target annotation, with source code available on GitHub.
Lane Williams[verified]@lanew44Disclosure
Sysdig’s Threat Research Team announced two new ingress‑nginx CVEs that could lead to configuration injection and remote code execution due to missing input sanitization. No PoC, exploit, or patch details are provided.
Lane Williams[verified]@lanew44Patch
The advisory identifies a path field injection flaw in NGINX Ingress Controller that enables remote code execution and other attacks, and it recommends upgrading to the patched versions immediately.
Open Source Security mailing list@oss_securityDisclosure
The text announces CVE-2026‑3288, a Kubernetes ingress‑nginx configuration injection that can result in arbitrary code execution and Secrets disclosure, providing a link to an openwall mailing‑list discussion and a CVSS score of 8.8.
Gray Hats@the_yellow_fallPatch
CVE‑2026‑3288 is a high‑severity ingress‑nginx flaw enabling arbitrary code execution and secret leakage; a patch is urgently recommended.