github.com
https://github.com/kubernetes/ingress-nginx CVE-2026-1580
HIGH
ingress-nginx auth-method nginx configuration injection
Record summary
CVE-2026-1580 has a selected CVSS score of 8.8 (high).
Description
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 5, 2026 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
ingress-nginxBrowse Kubernetes / ingress-nginxDefault status: affected | CVE List | Before 1.13.7 | affected |
| Before 1.14.3 | affected | ||
k8s.io/ingress-nginxBrowse Go / k8s.io/ingress-nginx | GitHub Advisory | Before 1.13.7 · Fixed in 1.13.7 | affected |
| 1.14.0 to < 1.14.3 · Fixed in 1.14.3 | affected |
References
3github.com
https://github.com/kubernetes/kubernetes/issues/136677 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-1580