logo

Detecting CVE-2026-3288 & CVE-2026-24512: Ingress-nginx configuration injection vulnerabilities for Kubernetes

ID: 46d1fa59-2626-5dba-a706-7344d33b4ee9

STIX ID: report--46d1fa59-2626-5dba-a706-7344d33b4ee9

Feed Name: Sysdig Blog

Threat Score
75/100

Date Published: 2026-03-17

Date Updated: 2026-05-01

...
...

Sysdig Threat Research analyzed CVE-2026-3288, a high-severity (CVSS 8.8) configuration-injection flaw in ingress-nginx where an unsanitized Ingress path containing a double-quote allows injection of arbitrary nginx directives (related to a prior incomplete fix for CVE-2026-24512), potentially enabling remote code execution and disclosure of secrets; fixes were released (v1.13.8 / v1.14.4 / v1.15.0), and Sysdig published a Falco detection rule plus mitigation and mitigation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.