Skip to content
F5CVE-2026-55723

When NGINX Ingress Controller is configured with Custom Resource Definitions

High8.7CVE-2026-55723 · Published Jul 15, 2026 · updated Jul 16, 2026

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

F5 advisory

Affected versions

PackageAffectedFixed in
NGINX Ingress Controller
Product
>= 5.0.0, < 5.5.25.5.2
>= 2026-lts-r1, < 2026-lts-r32026-lts-r3
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-76

More F5 advisories

All F5
Advisory
F5 NGINX: uninitialized resource
High8.8Jul 15
F5 NGINX: path traversal
Medium5.3Jul 15
F5 NGINX Plus: out-of-bounds read
Medium6.3Jul 15
F5 BIG-IP: denial of service
High8.7Jul 15
F5 NGINX: use after free
High8.3Jul 15
F5 NGINX Ingress Controller: denial of service
High7.1Jul 15

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.