Skip to content
F5CVE-2026-52865

F5 NGINX Ingress Controller: denial of service

High7.1CVE-2026-52865 · Published Jul 15, 2026 · updated Jul 16, 2026

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

F5 advisory

Affected versions

PackageAffectedFixed in
NGINX Ingress Controller
Product
>= 5.0.0, < 5.5.25.5.2
>= 2026-lts-r1, < 2026-lts-r32026-lts-r3
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-476

More F5 advisories

All F5
Advisory
F5 NGINX: uninitialized resource
High8.8Jul 15
F5 NGINX: path traversal
Medium5.3Jul 15
F5 NGINX Plus: out-of-bounds read
Medium6.3Jul 15
F5 BIG-IP: denial of service
High8.7Jul 15
When NGINX Ingress Controller is configured with Custom Resource Definitions
High8.7Jul 15
F5 NGINX: use after free
High8.3Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.