← Vulnerability feed

Vulnerability record · CVE-2026-3288 · published 9 March 2026

CVE-2026-3288: Kubernetes ingress-nginx improper input validation vulnerability

Kubernetes · Ingress Nginx

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

8.8 CVSS 3.1 High EPSS 0.71% · top 48.2% CWE-20 · Improper input validation
8.8CVSS 3.1 base score
0.71%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/kubernetes/kubernetes/issues/137560 Issue TrackingThird Party Advisory
http://www.openwall.com/lists/oss-security/2026/03/09/8 Mailing ListThird Party Advisory
https://github.com/bvabhishek/CVE-2026-3288-lab MitigationThird Party Advisory

Track CVE-2026-3288 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-5043Kubernetes ingress-nginx improper input validation vulnerabilityIngress nginx annotation injection causes arbitrary command execution.EPSS 2.2%8.8CVE-2023-5044ingress-nginx permanent-redirect annotation code injectionCVE-2023-5044 is a code injection flaw in ingress-nginx reached through the nginx.ingress.kubernetes.io/permanent-redirect annotation, caused by impr…EPSS 57%analysed8.1CVE-2021-25745Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path fi…EPSS 1.2%7.1CVE-2021-25746Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use .metadata.annotations in an Ingress o…EPSS 1.4%7.1CVE-2021-25742Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the custom snippets feature to obtain…EPSS 2.1%6.5CVE-2022-4886Kubernetes ingress-nginx improper input validation vulnerabilityIngress-nginx `path` sanitization can be bypassed with `log_format` directive.EPSS 1.6%6.5CVE-2021-25748Kubernetes ingress-nginx improper input validation vulnerabilityA security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use a newline character to bypass the san…EPSS 0.69%5.9CVE-2020-8553Kubernetes ingress-nginx vulnerabilityThe Kubernetes ingress-nginx component prior to version 0.28.0 allows a user with the ability to create namespaces and to read and create ingress obj…EPSS 0.89%

Source: NIST National Vulnerability Database (record CVE-2026-3288), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.