VYPR

NGINX Ingress Controller

by Nginx

CVEs (14)

  • CVE-2020-5901CriJul 1, 2020
    risk 0.63cvss 9.6epss 0.01

    In NGINX Controller 3.3.0-3.4.0, undisclosed API endpoints may allow for a reflected Cross Site Scripting (XSS) attack. If the victim user is logged in as admin this could result in a complete compromise of the system.

  • CVE-2020-5900HigJul 1, 2020
    risk 0.57cvss 8.8epss 0.00

    In versions 3.0.0-3.4.0, 2.0.0-2.9.0, and 1.0.1, there is insufficient cross-site request forgery (CSRF) protections for the NGINX Controller user interface.

  • CVE-2026-77180HigSep 2, 2026
    risk 0.54cvss 8.3epss 0.00

    When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An…

  • CVE-2025-14727HigDec 17, 2025
    risk 0.54cvss 8.3epss 0.00

    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23019HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.00

    The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

  • CVE-2020-5899HigJul 1, 2020
    risk 0.51cvss 7.8epss 0.00

    In NGINX Controller 3.0.0-3.4.0, recovery code required to change a user's password is transmitted and stored in the database in plain text, which allows an attacker who can intercept the database connection or have read access to the database, to request a password reset using…

  • CVE-2021-23018HigJun 1, 2021
    risk 0.48cvss 7.4epss 0.01

    Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using cleartext protocols inside the cluster.

  • CVE-2020-5864HigApr 23, 2020
    risk 0.48cvss 7.4epss 0.01

    In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

  • CVE-2022-30535MedAug 4, 2022
    risk 0.42cvss 6.5epss 0.01

    In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23055MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23021MedJun 1, 2021
    risk 0.36cvss 5.5epss 0.00

    The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.

  • CVE-2020-5865MedApr 23, 2020
    risk 0.31cvss 4.8epss 0.00

    In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.

  • CVE-2026-55723HigJul 15, 2026
    risk 0.00cvss 8.3epss 0.01

    When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX…

  • CVE-2026-52865MedJul 15, 2026
    risk 0.00cvss 6.5epss 0.01

    When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress…