{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3akubernetesnginx_ingress_controller/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kubernetes:nginx_ingress_controller:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-77180"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["NGINX Ingress Controller"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kubernetes"],"content_html":"\u003cp\u003eCVE-2026-77180 represents a security vulnerability in the NGINX Ingress Controller for Kubernetes, arising from improper sanitization of Ingress annotations during the configuration generation process. An authenticated attacker who possesses the necessary privileges to create or update Kubernetes Ingress objects can supply malicious input within specific annotation fields. These inputs are subsequently incorporated into the generated NGINX configuration files without adequate validation, effectively allowing the attacker to inject arbitrary NGINX directives.\u003c/p\u003e\n\u003cp\u003eThis issue is classified as a control plane vulnerability rather than a data plane exposure, meaning the impact is limited to the configuration logic of the ingress controller itself. Successful exploitation enables an attacker to manipulate server behavior, which may lead to service disruption, unauthorized modification of the NGINX configuration, or potential interaction with the underlying filesystem depending on the injected directives. Defenders should note that this vulnerability requires prior authorization within the Kubernetes cluster, making it an escalation or misuse path rather than a simple unauthenticated remote code execution.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows for the modification of the NGINX Ingress Controller configuration, which can lead to service denial, arbitrary file system manipulation, or unauthorized changes to traffic routing rules within the cluster. Because it affects the control plane of the Kubernetes Ingress mechanism, the scope of impact is potentially cluster-wide for environments where users are granted broad permissions to manage Ingress resources.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImplement strict Kubernetes RBAC policies to limit which users or service accounts have permission to create or update Ingress objects.\u003c/li\u003e\n\u003cli\u003eApply Admission Controllers or Validating Webhooks to sanitize or reject Ingress annotations containing suspicious characters (e.g., newline characters, semicolon delimiters, or unauthorized directive keywords).\u003c/li\u003e\n\u003cli\u003eUpdate NGINX Ingress Controller to the latest security-patched release provided by the vendor.\u003c/li\u003e\n\u003cli\u003eReview current Ingress configurations for unusual or non-standard annotation usage using the Kubernetes API audit logs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-02T17:15:32Z","date_published":"2026-09-02T17:15:32Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nginx-ingress-injection/","summary":"Authenticated attackers can exploit an injection vulnerability in the NGINX Ingress Controller for Kubernetes by injecting arbitrary configuration directives via Ingress annotations.","title":"CVE-2026-77180 - NGINX Ingress Controller Configuration Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-nginx-ingress-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:kubernetes:nginx_ingress_controller:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}