VYPR

NGINX Ingress Controller

by Nginx

CVEs (7)

  • CVE-2025-14727HigDec 17, 2025
    risk 0.54cvss 8.3epss 0.00

    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23019HigJun 1, 2021
    risk 0.51cvss 7.8epss 0.00

    The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file that is included in the NGINX support package.

  • CVE-2020-5864HigApr 23, 2020
    risk 0.48cvss 7.4epss 0.01

    In versions of NGINX Controller prior to 3.2.0, communication between NGINX Controller and NGINX Plus instances skip TLS verification by default.

  • CVE-2022-30535MedAug 4, 2022
    risk 0.42cvss 6.5epss 0.01

    In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23055MedApr 21, 2022
    risk 0.42cvss 6.5epss 0.01

    On version 2.x before 2.0.3 and 1.x before 1.12.3, the command line restriction that controls snippet use with NGINX Ingress Controller does not apply to Ingress objects. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

  • CVE-2021-23021MedJun 1, 2021
    risk 0.36cvss 5.5epss 0.00

    The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with current permission bits set to 644.

  • CVE-2020-5865MedApr 23, 2020
    risk 0.31cvss 4.8epss 0.00

    In versions prior to 3.3.0, the NGINX Controller is configured to communicate with its Postgres database server over unencrypted channels, making the communicated data vulnerable to interception via man-in-the-middle (MiTM) attacks.