CVE-2026-4342Disclosure(kubernetes / nginx_ingress_controller)

MEDIUMCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch kubernetes nginx_ingress_controller systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • nginx_ingress_controller

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 28 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 25 signals
  • Disclosure: 11 classified signals
  • General: 6 classified signals
  • Peaked 5d ago at 9 mentions (2026-03-20); latest day: 1
  • 28 total mentions across 7 days

Affected systems

Vendors
Products
nginx_ingress_controller

1 version affected across 1 product

Deep dive

Activity timeline28 mentions / 7d
02579Mentions · 2026-03-19: 5Mentions · 2026-03-20: 9Mentions · 2026-03-22: 2Mentions · 2026-03-23: 2Mentions · 2026-03-31: 1Mentions · 2026-04-08: 8Mentions · 2026-06-19: 1PoC Mentioned / Linked · 2026-03-20: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-04-08: 1Exploit Tool / Code · 2026-03-23: 1Exploit Tool / Code · 2026-04-08: 1Patch / Workaround · 2026-03-19: 1Patch / Workaround · 2026-03-20: 2Patch / Workaround · 2026-03-22: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-08: 6Patch / Workaround · 2026-06-19: 1Technical Details · 2026-03-19: 5Technical Details · 2026-03-20: 8Technical Details · 2026-03-22: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-08: 8Technical Details · 2026-06-19: 103-1903-2003-2203-2303-3104-0806-19
Signal classification4 categories
Disclosure
1139.3%
Patch
932.1%
General
621.4%
PoC
27.1%
Referenced assets18 URLs
Classification over time
DateTotalLabels
2026-03-195
Disclosure3General1Patch1
2026-03-209
Disclosure3General4Patch2
2026-03-222
Disclosure1Patch1
2026-03-232
General1PoC1
2026-03-311
Patch1
2026-04-088
Disclosure3Patch4PoC1
2026-06-191
Disclosure1
Full discourse20 posts
  • Kubernetes@kubernetesio
    Patch

    🚨 A high-vulnerability CVE (CVE-2026-4342) has been identified in ingress-nginx. This vulnerability enables configuration injection and potential code execution on all versions below v1.13.9, v1.14.5, and v1.15.1. As ingress-nginx is now EOL (End of Life), users are strongly encouraged to upgrade and migrate immediately. Details: https://github.com/kubernetes/kubernetes/issues/137893

    Post summary

    CVE‑2026‑4342 is a high‑severity vulnerability in ingress‑nginx that allows configuration injection and potential code execution in versions before v1.13.9, v1.14.5, and v1.15.1, with users urged to upgrade as the product is now end‑of‑life.

    26255291.5K612272.0K
    324.0K followersView on X
  • dbugs@ptdbugs
    PoC

    🔔 A PoC/exploit has been discovered for vulnerability CVE-2026-4342 Vendor: Kubernetes Product: ingress-nginx Description: A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.) Link: https://github.com/stuartMoorhouse/CVE-2026-4342 #dbugs_vuln

    Post summary

    A PoC and exploit code for CVE-2026-4342 in ingress-nginx has been released, demonstrating arbitrary code execution via Ingress annotation injection and Secrets disclosure. No patch or evidence of active exploitation is reported.

    19050184.0K
    733 followersView on X
  • Kubernetes@kubernetesio
    Disclosure

    CVE-2026-4342: ingress-nginx comment-based nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/137893

    Post summary

    The tweet links to a GitHub discussion about CVE‑2026‑4342, highlighting a comment‑based configuration injection flaw in ingress‑nginx, but provides no exploit code, patch, or evidence of active exploitation.

    17051188.8K
    320.2K followersView on X
  • K8sContributors@K8sContributors
    Disclosure

    CVE-2026-4342: ingress-nginx comment-based nginx configuration injection - https://github.com/kubernetes/kubernetes/issues/137893

    Post summary

    The post announces CVE-2026-4342 as a comment‑based nginx configuration injection vulnerability, but offers no proof of concept, exploit code, evidence of active attacks, or patch information.

    03093676
    16.0K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    A high-severity 8.8 CVSS flaw (CVE-2026-4342) in ingress-nginx allows attackers to inject malicious code and steal Kubernetes Secrets. Patch immediately #IngressNginx #KubernetesSecurity #CVE #CyberSecurity #CloudSecurity #InfoSec #Vulnerability #DevSecOps https://securityonline.info/annotation-trap-high-severity-ingress-nginx-flaw-cve-2026-4342/ https://t.co/tCbPIBdz2L

    Post summary

    The tweet alerts to CVE‑2026‑4342, a high‑severity flaw in ingress‑nginx that allows malicious code injection and Kubernetes secret theft, and urges an immediate patch.

    03082492
    10.7K followersView on X
  • NanoVMs@nanovms
    General

    this week on containers can't contain, wait we already did one this wk... the kubernetes security team once again outdoes themselves by posting a 8.8 - CVE-2026-4342 - with no data on http://cve.org || nvd - great job!

    Post summary

    The tweet mentions a new Kubernetes CVE (CVE-2026-4342) with a severity score of 8.8, but offers no further technical detail, exploit code, patch info, or evidence of active exploitation.

    12060381
    2.0K followersView on X
  • Open Source Security mailing list@oss_security
    Disclosure

    CVE-2026-4342: Kubernetes: ingress-nginx comment-based nginx configuration injection https://www.openwall.com/lists/oss-security/2026/03/19/9 can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller

    Post summary

    The post announces a comment‑based nginx configuration injection in Kubernetes ingress‑nginx, which can cause arbitrary code execution and secret disclosure, but offers no exploit code, active‑exploitation evidence, or remedy details.

    04041434
    4.4K followersView on X
  • kubesimplify@kubesimplify
    Disclosure

    If you're running ingress-nginx v1.13.x < 1.13.9, v1.14.x < 1.14.5, or v1.15.x < 1.15.1, you might have a critical security hole in your control plane. CVE-2026-4342 (CVSS 8.8) allows remote exploitation with low privileges and zero user interaction. It’s patched now, but the exposure is massive.

    Post summary

    The post announces a critical CVE (2026‑4342) affecting various ingress‑nginx versions, highlights the severity (CVSS 8.8 with remote exploitation), and notes that a patch is now available.

    11030801
    12.6K followersView on X
  • Grok@grok
    PoC

    CVE-2026-4342 (CVSS 8.8) lets attackers with low-priv K8s API access (e.g., create Ingress) inject malicious nginx config via annotation combos. Result: RCE in ingress-nginx controller + full access to cluster Secrets (default: all). Exploit: Moderate difficulty. Needs API perms (common for devs/tenants); no unauth remote vector. PoC now public, so feasible for insiders or compromised accounts. Estimate: ingress-nginx powers ~40% of K8s clusters (per historical scans). With EOL status + slow patching, 100k–1M+ envs likely affected globally, esp. enterprise/ cloud setups on pre-1.13.9/1.14.5/1.15.1. Upgrade ASAP.

    Post summary

    CVE-2026-4342 allows low‑privileged K8s users to inject malicious nginx configs, enabling RCE and secret access. A publicly available PoC and recommended patch highlight the vulnerability’s impact.

    010311.1K
    8.6M followersView on X
  • Vito Botta@vitobotta
    Patch

    Another Kubernetes ingress-nginx vulnerability - CVE-2026-4342 (CVSS 8.8). A clever combo of Ingress annotations can inject arbitrary nginx config, leading to RCE and cluster-wide Secret disclosure. The controller can access ALL Secrets by default. Patch to v1.13.9, v1.14.5, or v1.15.1 immediately if you're running ingress-nginx and seriously, it's time to migrate to something else as ingress-nginx is a dead project.

    Post summary

    The post alerts about CVE‑2026‑4342, describing an RCE through annotation injection and Secret disclosure, and provides specific patch versions to remediate the issue.

    01121450
    1.0K followersView on X
  • kokumօtօ@__kokumoto
    Patch

    ingress-nginxにインジェクションの脆弱性。CVE-2026-4342は一連のIngressアノテーションを使用することで、基底となっているNginx構成ファイルにスニペットを注入できるもの。ingress-nginxコンテキストでの任意コード実行が可能。修正版提供あり。 https://securityonline.info/annotation-trap-high-severity-ingress-nginx-flaw-cve-2026-4342/

    Post summary

    CVE-2026-4342 is an injection vulnerability in ingress-nginx that allows arbitrary code execution through Ingress annotations, and a fix has been released.

    01022992
    7.3K followersView on X
  • Onix React@onix_react
    Disclosure

    🚨 𝗦𝗲𝗰𝘂𝗿𝗶𝘁𝘆 𝗔𝗹𝗲𝗿𝘁: 𝗶𝗻𝗴𝗿𝗲𝘀𝘀-𝗻𝗴𝗶𝗻𝘅 A high-severity vulnerability (CVE-2026-4342) allows configuration injection and possible remote code execution in versions below v1.13.9, v1.14.5, and v1.15.1. Details: https://github.com/kubernetes/kubernetes/issues/137893

    Post summary

    CVE-2026-4342 is a high‑severity configuration injection vulnerability that may lead to remote code execution in older Kubernetes releases; the post announces the vulnerability and lists affected versions but offers no PoC, exploit, or patch details.

    0003069
    73 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en productos Ingress-NGINX ❗ CVE-2026-4342 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-productos-ingress-nginx/ https://t.co/EmAQuriuuQ

    Post summary

    The post announces CVE-2026-4342 affecting Ingress-NGINX and links to a source for more information, but it offers no technical, patch, or exploitation details.

    01010102
    6.6K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: High severity nginx Config Injection in #IngressNginx #Kubernetes. #CVE-2026-4342 CVSS: 8.8. Malicious Ingress annotations can be used to inject configuration which will lead to arbitrary code execution in the controller. https://ccb.belgium.be/advisories/warning-arbitrary-code-execution-kubernetes-ingress-nginx-patch-immediately #Patch #Patch #Patch

    Post summary

    The tweet warns of a newly disclosed high-severity nginx config injection CVE (CVE-2026-4342) and urges immediate patching, providing technical details but no proof of exploitation.

    01001228
    7.2K followersView on X
  • dbugs@ptdbugs
    General

    ingress-nginx comment-based nginx configuration injection CVE: CVE-2026-4342 Vendor: Kubernetes Product: ingress-nginx CVSS: 8.8 Credits: wooseokdotkim Description: A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.) References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-4342 • https://github.com/kubernetes/kubernetes/issues/137893 #dbugs_vuln

    Post summary

    The text highlights CVE‑2026‑4342, explaining how annotation-based injection can result in code execution and Secrets leakage, but does not provide a PoC, exploit code, active exploitation evidence, or patch information.

    0001177
    649 followersView on X
  • VulnTracker@vuln_tracker
    General

    @kubernetesio CVE-2026-4342 dropping for ingress-nginx is concerning - comment-based config injection means attackers could potentially bypass security controls through nginx configuration manipulation. Monitor Kubernetes vulnerabilities: http://vulntracker.io

    Post summary

    The tweet highlights that CVE‑2026‑4342 permits comment‑based configuration injection in ingress‑nginx, potentially bypassing security controls, but provides no proof‑of‑concept, exploit code, patch, or evidence of active exploitation.

    00001458
    442 followersView on X
  • Justin Kwon@ju571nK
    Disclosure

    Kubernetes Ingress-NGINX に設定インジェクションの脆弱性 CVE-2026-4342(CVSS 8.8)。コントローラ権限での任意コード実行とSecret漏洩につながる恐れ。運用中なら優先的にパッチを。 #セキュリティ #Kubernetes #クラウドセキュリティ #CVE https://www.runzero.com/blog/k8s-ingress-nginx-controller/

    Post summary

    The post announces a high‑severity configuration injection flaw (CVE-2026-4342) in Kubernetes Ingress‑NGINX that could allow code execution and secret leaks, and urges immediate patching.

    0000093
    5 followersView on X
  • 🪐 Hackwy.eth | Security✨@JawyPinto
    Patch

    CVE-2026-4342 es crítica — configuration injection en ingress-nginx permite RCE en cualquier cluster que no haya actualizado. Si usas versiones anteriores a v1.13.9, v1.14.5 o v1.15.1 → actualiza YA. ingress-nginx ya es EOL. Consideren migrar a alternatives como Envoy Gateway o Traefik.

    Post summary

    CVE-2026-4342 is a critical configuration injection flaw in ingress‑nginx that allows RCE; users are advised to upgrade to v1.13.9, v1.14.5, or v1.15.1 or migrate to alternatives such as Envoy Gateway or Traefik.

    0000074
    474 followersView on X
  • Leandro Alves | IA@FalandoDeCodigo
    Patch

    🚨 ALERTA CRÍTICO: CVE-2026-4342 NO KUBERNETES INGRESS-NGINX 🚨 Uma vulnerabilidade de altíssima severidade acaba de ser confirmada no `ingress-nginx`. A falha (CVE-2026-4342) permite injeção de configuração e execução arbitrária de código (RCE) em clusters que rodem versões abaixo da v1.13.9, v1.14.5 e v1.15.1. O fator mais crítico: o `ingress-nginx` atingiu seu End of Life (EOL). Se o tráfego da sua infraestrutura Kubernetes ainda passa por ele sem os patches recentes, os seus clusters estão expostos a ataques massivos de RCE logo na porta de entrada da sua rede. A engenharia de plataforma não perdoa negligência com componentes core. Auditem suas frotas, apliquem o patch de mitigação imediatamente ou comecem a migração do ingress controller para alternativas ativamente suportadas. A hora de agir é agora. 🛡️⚙️ #Kubernetes #K8s #DevOps #CyberSecurity #AppSec https://x.com/kubernetesio/status/2041698295647453575

    Post summary

    The message warns of a high‑severity RCE flaw (CVE‑2026‑4342) in the end‑of‑life ingress‑nginx component, urges immediate patching, and does not provide evidence of active exploitation or a PoC.

    0000069
    24 followersView on X
  • SAIM SAFDAR@cloudnativeboy
    Disclosure

    🚨 A high-vulnerability CVE (CVE-2026-4342) has been identified in ingress-nginx. This vulnerability enables configuration injection and potential code execution on all versions below v1.13.9, v1.14.5, and v1.15.1. Details: https://github.com/kubernetes/kubernetes/issues/137893

    Post summary

    The tweet announces a new ingress‑nginx vulnerability (CVE‑2026‑4342) with details on its impact and affected versions, but does not provide PoC, exploit code, active exploitation claims, or patch information.

    00000132
    2.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appkubernetesnginx_ingress_controller---
Appkubernetesnginx_ingress_controller1.15.0--

Explore more