k8s.io/ingress-nginx has critical vulnerabilities — do not use
Update to >= 0.0.0-20260319175635-5183b7d86137 to fix known vulnerabilities
| Severity | ID | Summary | Fixed in |
|---|---|---|---|
| medium | BIT-nginx-ingress-controller-2025-24513 | ingress-nginx controller - auth secret file path traversal vulnerability | 1.12.1 |
| medium | BIT-nginx-ingress-controller-2026-24514 | ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling | 1.14.3 |
| low | BIT-nginx-ingress-controller-2026-24513 | ingress-nginx has Improper Check for Unusual or Exceptional Conditions | 1.14.3 |
| high | BIT-nginx-ingress-controller-2023-5043 | Ingress nginx annotation injection causes arbitrary command execution | 1.9.0 |
| high | BIT-nginx-ingress-controller-2025-1097 | ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation | 1.12.1 |
| medium | BIT-nginx-ingress-controller-2021-25748 | Ingress-nginx `path` sanitization can be bypassed with newline character | 1.2.1 |
| high | BIT-nginx-ingress-controller-2026-1580 | ingress-nginx's `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx | 1.14.3 |
| high | BIT-nginx-ingress-controller-2026-4342 | ingress-nginx comment-based nginx configuration injection | 0.0.0-20260319175635-5183b7d86137 |
| high | BIT-nginx-ingress-controller-2023-5044 | Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation | 1.9.0 |
| high | BIT-nginx-ingress-controller-2025-24514 | ingress-nginx controller - configuration injection via unsanitized auth-url annotation | 1.12.1 |
| high | BIT-nginx-ingress-controller-2022-4886 | Ingress-nginx path sanitization can be bypassed | 1.8.0 |
| medium | BIT-nginx-ingress-controller-2020-8553 | ingress-nginx component for Kubernetes allows file overwrite | 0.28.0 |
| high | BIT-nginx-ingress-controller-2026-24512 | ingress-nginx's `rules.http.paths.path` Ingress field can be used to inject configuration into nginx | 1.14.3 |
| critical | BIT-nginx-ingress-controller-2025-1974 | ingress-nginx admission controller RCE escalation | 1.12.1 |
| medium | CVE-2018-1002104 | Kubernetes ingress exposes sensitive information | 1.5 |
| high | BIT-nginx-ingress-controller-2021-25745 | Improper Input Validation in k8s.io/ingress-nginx | 1.2.0 |
| high | BIT-nginx-ingress-controller-2025-1098 | ingress-nginx controller - configuration injection via unsanitized mirror annotations | 1.12.1 |
| unknown | BIT-nginx-ingress-controller-2023-5044 | Ingress-nginx code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation in k8s.io/ingress-nginx | — |
| unknown | BIT-nginx-ingress-controller-2025-24513 | ingress-nginx controller - auth secret file path traversal vulnerability in k8s.io/ingress-nginx | — |
| unknown | BIT-nginx-ingress-controller-2025-1097 | ngress-nginx controller - configuration injection via unsanitized auth-tls-match-cn annotation in k8s.io/ingress-nginx | — |
Get this data programmatically — free, no authentication.
curl https://depscope.dev/api/check/go/k8s.io/ingress-nginxLast updated · 2026-03-19T21:20:31Z