Skip to content
F5CVE-2026-77180

When NGINX Ingress Controller is configured with Ingress annotations

High8.7CVE-2026-77180 · Published Sep 2, 2026 · updated Sep 3, 2026

When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

F5 advisory

Affected versions

PackageAffectedFixed in
NGINX Ingress Controller
Product
>= 5.0.0, < 5.6.05.6.0
>= 2026-lts-r1, < 2026-lts-r52026-lts-r5
Details and references
CVSS 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-76

More F5 advisories

All F5
Advisory
F5 NGINX JavaScript: out-of-bounds write
Critical9.2Sep 2
F5 NGINX JavaScript: denial of service
High8.7Sep 2
F5 BIG-IP: attacker could spoof error messages Impact: An attacker may
Low2.3Sep 2
Description: When NGINX Plus is configured as the data plane for NGINX Gateway...
High8.6Sep 2
F5 BIG-IP: privilege escalation
High8.7Sep 2
Description NGINX JavaScript
High8.8Sep 2

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.