Record summary

CVE-2026-1580 has a selected CVSS score of 8.8 (high).

Description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2026 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus

Default status: affected

CVE ListBefore 1.13.7affected
Before 1.14.3affected
GitHub AdvisoryBefore 1.13.7 · Fixed in 1.13.7affected
1.14.0 to < 1.14.3 · Fixed in 1.14.3affected

References

3