À la une
Veille
Sécurité
DevOps
Cloud
IA
Self-hosted
Linux
Réseau
Rechercher
⌘K
EN
en direct
CVE-2025-15662 · CVSS 8.6
CVE-2025-50455 · CVSS 9.1
CVE-2025-59172 · CVSS 8.5
CVE-2025-68686 · Fortinet FortiOS
accueil
veille
CWE-76
type de faiblesse
CWE-76
1
vulnérabilité suivie
15 juillet 2026
dernière publication
Éditeurs les plus touchés
F5 · 1
cve
Veille des vulnérabilités
identifiant
vulnérabilité
sévérité
publié
CVE-2026-55723
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
F5 Nginx Ingress Controller
Élevée
CVSS 8.3
15/07
← Retour à la veille
Fiche CWE sur mitre.org →
esc
Tapez au moins deux caractères.
↑
↓
naviguer
↵
ouvrir
esc
fermer