GHSA-pvmg-xgmx-9mxh
GitHub Security Advisory
Improper Input Validation in k8s.io/ingress-nginx
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
A security issue was discovered in ingress-nginx where a user that can create or update ingress objects can use the spec.rules[].http.paths[].path field of an Ingress object (in the networking.k8s.io or extensions API group) to obtain the credentials of the ingress-nginx controller. In the default configuration, that credential has access to all secrets in the cluster.
Affected Packages
Go
k8s.io/ingress-nginx
Affected versions:
0
(fixed in 1.2.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: November 24, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.