← Vulnerability feed

Vulnerability record · CVE-2023-5044 · published 25 October 2023

CVE-2023-5044: ingress-nginx permanent-redirect annotation code injection

Kubernetes · Ingress Nginx

CVE-2023-5044 is a code injection flaw in ingress-nginx reached through the nginx.ingress.kubernetes.io/permanent-redirect annotation, caused by improper input validation (CWE-20, CWE-94). An actor able to set that annotation can inject code into the generated nginx configuration, which matters because ingress-nginx sits in the request path for cluster traffic.

8.8 CVSS 3.1 High EPSS 57% · top 1.0% CWE-20 · Improper input validationCWE-94 · Code injection
8.8CVSS 3.1 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Code injection via nginx.ingress.kubernetes.io/permanent-redirect annotation.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with high EPSS (99th percentile) and network reachability, though exploitation requires the low-level privilege of modifying Ingress annotations and no KEV listing exists.

What it is

CVE-2023-5044 is a code injection flaw in ingress-nginx reached through the nginx.ingress.kubernetes.io/permanent-redirect annotation, caused by improper input validation (CWE-20, CWE-94). An actor able to set that annotation can inject code into the generated nginx configuration, which matters because ingress-nginx sits in the request path for cluster traffic.

Impact

Successful exploitation gives code execution in the ingress-nginx context with high confidentiality, integrity and availability impact per the CVSS vector. The attacker gains control over the ingress controller's behavior rather than only a redirect.

Attack surface

Reached over the network (AV:N) with low attack complexity and no user interaction; the vector requires low privileges (PR:L), consistent with an actor who can create or modify Ingress resources and their annotations. No authentication bypass is implied beyond those privileges.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is 0.56605 (99th percentile), indicating elevated predicted exploitation activity; references are vendor advisories and mitigation guidance rather than public exploit code.

What to do

  • Upgrade ingress-nginx to a version that fixes the annotation handling, following the vendor advisory and Kubernetes security announcement.
  • Restrict who can create or modify Ingress objects and annotations via RBAC, limiting write access to trusted operators.
  • Admission-control or policy checks that reject or sanitize the nginx.ingress.kubernetes.io/permanent-redirect annotation from untrusted sources.
  • Audit existing Ingress resources for unexpected or attacker-controlled permanent-redirect annotation values and remove them.

Detection

  • Monitor Kubernetes audit logs for create/update/patch events on Ingress resources that set or change the permanent-redirect annotation.
  • Alert on RBAC changes granting Ingress write permissions to new or unexpected subjects.
  • Review generated nginx configuration in ingress-nginx pods for unexpected directives or injected content.
  • Watch ingress-nginx logs and process behavior for anomalies following annotation changes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-5044 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-3288Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject conf…EPSS 0.71%8.8CVE-2023-5043Kubernetes ingress-nginx improper input validation vulnerabilityIngress nginx annotation injection causes arbitrary command execution.EPSS 2.2%8.1CVE-2021-25745Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…EPSS 1.2%7.1CVE-2021-25746Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o…EPSS 1.4%7.1CVE-2021-25742Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain…EPSS 2.1%6.5CVE-2022-4886Kubernetes ingress-nginx improper input validation vulnerabilityIngress-nginx `path` sanitization can be bypassed with `log_format` directive.EPSS 1.6%6.5CVE-2021-25748Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…EPSS 0.69%5.9CVE-2020-8553Kubernetes ingress-nginx vulnerabilityThe Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress obj…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2023-5044), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.