Ingress-NGINX Flaw Enables Arbitrary Code Execution Attacks
ID: ca69d171-66e0-50ec-a83c-ac6521f4e6a2
STIX ID: report--ca69d171-66e0-50ec-a83c-ac6521f4e6a2
Feed Name: GBHackers
Threat Score
**CVE-2026-24512 — ingress-nginx path injection (CVSS 8.8):** A high-severity vulnerability in the Kubernetes ingress-nginx controller allows configuration injection via the rules.http.paths.path field, potentially enabling arbitrary code execution and access to cluster secrets; affected versions are all releases before v1.13.7 and v1.14.3, and administrators are advised to upgrade to the patched releases immediately and monitor Ingress objects for anomalous path values.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
