Search

Find a vulnerability

Search criteria

    20 vulnerabilities found for NGINX Ingress Controller by F5

    CERTFR-2026-AVI-1182

    Vulnerability from certfr_avis - Published: 2026-09-16 - Updated: 2026-09-17

    Une vulnérabilité a été découverte dans F5 NGINX. Elle permet à un attaquant de provoquer un déni de service à distance et une atteinte à l'intégrité des données.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    F5 NGINX NGINX Open Source versions antérieures à 1.30.5
    F5 NGINX NGINX Open Source versions 1.31.x antérieures à 1.31.6
    F5 NGINX Plus NGINX Plus versions 37.x antérieures à 37.0.6.2
    F5 NGINX Plus NGINX Plus versions 37.1.x antérieures à 37.1.1.2
    F5 NGINX Ingress Controller NGINX Ingress Controller versions antérieures à 5.6.3
    F5 NGINX Gateway Fabric NGINX Gateway Fabric versions 2.x antérieures à 2.7.2
    References
    Bulletin de sécurité F5 K000162604 2026-09-15 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NGINX Open Source versions ant\u00e9rieures \u00e0 1.30.5",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Open Source versions 1.31.x ant\u00e9rieures \u00e0 1.31.6",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Plus versions 37.x ant\u00e9rieures \u00e0 37.0.6.2",
          "product": {
            "name": "NGINX Plus",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Plus versions 37.1.x ant\u00e9rieures \u00e0 37.1.1.2",
          "product": {
            "name": "NGINX Plus",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions ant\u00e9rieures \u00e0 5.6.3",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Gateway Fabric versions 2.x ant\u00e9rieures \u00e0 2.7.2",
          "product": {
            "name": "NGINX Gateway Fabric",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-90439",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-90439"
        }
      ],
      "initial_release_date": "2026-09-16T00:00:00",
      "last_revision_date": "2026-09-17T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1182",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-16T00:00:00.000000"
        },
        {
          "description": "Ajouts de syst\u00e8mes affect\u00e9s suppl\u00e9mentaires pour refl\u00e9ter la mise \u00e0 jour du bulletin de l\u0027\u00e9diteur.",
          "revision_date": "2026-09-17T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans F5 NGINX. Elle permet \u00e0 un attaquant de provoquer un d\u00e9ni de service \u00e0 distance et une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.",
      "title": "Vuln\u00e9rabilit\u00e9 dans F5 NGINX",
      "vendor_advisories": [
        {
          "published_at": "2026-09-15",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162604",
          "url": "https://my.f5.com/manage/s/article/K000162604"
        }
      ]
    }

    CERTFR-2026-AVI-1111

    Vulnerability from certfr_avis - Published: 2026-09-03 - Updated: 2026-09-03

    De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    F5 BIG-IP BIG-IP versions 21.1.x antérieures à 21.1.0.1
    F5 BIG-IP BIG-IP APM versions 17.1.x antérieures à 17.1.3.1
    F5 NGINX NGINX Gateway Fabric versions 2.x antérieures à 2.6.8
    F5 BIG-IP BIG-IQ versions 8.4.x antérieures à 8.4.2.1
    F5 BIG-IP BIG-IP versions 17.1.x antérieures à 17.1.3.4
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 5.x antérieures à 5.6.0
    F5 BIG-IP BIG-IP APM versions 17.5.x antérieures à 17.5.1.4
    F5 BIG-IP BIG-IP versions 17.5.x antérieures à 17.5.1.8
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 2026-lts-rx antérieures à 2026-lts-r5
    F5 BIG-IP APM Clients versions 7.2.x antérieures à 7.2.6
    F5 BIG-IP BIG-IP versions 21.0.x antérieures à 21.0.0.3
    F5 NGINX NGINX JavaScript versions antérieures à 1.0.1
    References
    Bulletin de sécurité F5 K000162601 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162417 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162872 2026-09-02 vendor-advisory
    Bulletin de sécurité F5 K000162521 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162602 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162599 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000161728 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162600 2026-09-03 vendor-advisory
    Bulletin de sécurité F5 K000162603 2026-09-03 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "BIG-IP versions 21.1.x ant\u00e9rieures \u00e0 21.1.0.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP APM versions 17.1.x ant\u00e9rieures \u00e0 17.1.3.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Gateway Fabric versions 2.x ant\u00e9rieures \u00e0 2.6.8",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IQ versions 8.4.x ant\u00e9rieures \u00e0 8.4.2.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP versions 17.1.x ant\u00e9rieures \u00e0 17.1.3.4",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 5.x ant\u00e9rieures \u00e0 5.6.0",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP APM versions 17.5.x ant\u00e9rieures \u00e0 17.5.1.4",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP versions 17.5.x ant\u00e9rieures \u00e0 17.5.1.8",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 2026-lts-rx ant\u00e9rieures \u00e0 2026-lts-r5",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "APM Clients versions 7.2.x ant\u00e9rieures \u00e0 7.2.6",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP versions 21.0.x ant\u00e9rieures \u00e0 21.0.0.3",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX JavaScript versions ant\u00e9rieures \u00e0 1.0.1",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2026-18329",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-18329"
        },
        {
          "name": "CVE-2026-66842",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66842"
        },
        {
          "name": "CVE-2026-42959",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-42959"
        },
        {
          "name": "CVE-2026-77180",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-77180"
        },
        {
          "name": "CVE-2026-78689",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78689"
        },
        {
          "name": "CVE-2026-78222",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-78222"
        },
        {
          "name": "CVE-2026-33278",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-33278"
        },
        {
          "name": "CVE-2026-63020",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-63020"
        },
        {
          "name": "CVE-2026-66362",
          "url": "https://www.cve.org/CVERecord?id=CVE-2026-66362"
        }
      ],
      "initial_release_date": "2026-09-03T00:00:00",
      "last_revision_date": "2026-09-03T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-1111",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-09-03T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Non sp\u00e9cifi\u00e9 par l\u0027\u00e9diteur"
        },
        {
          "description": "Falsification de requ\u00eates c\u00f4t\u00e9 serveur (SSRF)"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5. Certaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une ex\u00e9cution de code arbitraire \u00e0 distance, une \u00e9l\u00e9vation de privil\u00e8ges et un d\u00e9ni de service \u00e0 distance.",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
      "vendor_advisories": [
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162601",
          "url": "https://my.f5.com/manage/s/article/K000162601"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162417",
          "url": "https://my.f5.com/manage/s/article/K000162417"
        },
        {
          "published_at": "2026-09-02",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162872",
          "url": "https://my.f5.com/manage/s/article/K000162872"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162521",
          "url": "https://my.f5.com/manage/s/article/K000162521"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162602",
          "url": "https://my.f5.com/manage/s/article/K000162602"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162599",
          "url": "https://my.f5.com/manage/s/article/K000162599"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000161728",
          "url": "https://my.f5.com/manage/s/article/K000161728"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162600",
          "url": "https://my.f5.com/manage/s/article/K000162600"
        },
        {
          "published_at": "2026-09-03",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000162603",
          "url": "https://my.f5.com/manage/s/article/K000162603"
        }
      ]
    }

    CERTFR-2026-AVI-0047

    Vulnerability from certfr_avis - Published: 2026-01-15 - Updated: 2026-01-15

    Une vulnérabilité a été découverte dans F5 NGINX Ingress Controller. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 5.x antérieures à 5.3.1
    References
    Bulletin de sécurité F5 K000158176 2025-12-17 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NGINX Ingress Controller versions 5.x ant\u00e9rieures \u00e0 5.3.1",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2025-14727",
          "url": "https://www.cve.org/CVERecord?id=CVE-2025-14727"
        }
      ],
      "initial_release_date": "2026-01-15T00:00:00",
      "last_revision_date": "2026-01-15T00:00:00",
      "links": [],
      "reference": "CERTFR-2026-AVI-0047",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2026-01-15T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans F5 NGINX Ingress Controller. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans F5 NGINX Ingress Controller",
      "vendor_advisories": [
        {
          "published_at": "2025-12-17",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000158176",
          "url": "https://my.f5.com/manage/s/article/K000158176"
        }
      ]
    }

    CERTFR-2024-AVI-0952

    Vulnerability from certfr_avis - Published: 2024-11-08 - Updated: 2024-11-08

    Une vulnérabilité a été découverte dans les produits F5. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    Solutions

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    Impacted products
    Vendor Product Description
    F5 NGINX Ingress Controller NGINX Ingress Controller versions antérieures à 3.7.1
    F5 NGINX Plus NGINX Plus toutes versions
    F5 NGINX API Connectivity Manager NGINX API Connectivity Manager versions 1.x postérieures à 1.3.0 et antérieures à 1.9.3
    F5 NGINX Instance Manager NGINX Instance Manager versions 2.x postérieures à 2.5.0 et antérieures à 2.17.4
    References
    Bulletin de sécurité F5 K000148232 2024-11-06 vendor-advisory

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NGINX Ingress Controller versions ant\u00e9rieures \u00e0 3.7.1",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Plus toutes versions",
          "product": {
            "name": "NGINX Plus",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX API Connectivity Manager versions 1.x post\u00e9rieures \u00e0 1.3.0 et ant\u00e9rieures \u00e0 1.9.3",
          "product": {
            "name": "NGINX API Connectivity Manager",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Instance Manager versions 2.x post\u00e9rieures \u00e0 2.5.0 et ant\u00e9rieures \u00e0 2.17.4",
          "product": {
            "name": "NGINX Instance Manager",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": "",
      "content": "## Solutions\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des correctifs (cf. section Documentation).",
      "cves": [
        {
          "name": "CVE-2024-10318",
          "url": "https://www.cve.org/CVERecord?id=CVE-2024-10318"
        }
      ],
      "initial_release_date": "2024-11-08T00:00:00",
      "last_revision_date": "2024-11-08T00:00:00",
      "links": [],
      "reference": "CERTFR-2024-AVI-0952",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2024-11-08T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans les produits F5. Elle permet \u00e0 un attaquant de provoquer un contournement de la politique de s\u00e9curit\u00e9.",
      "title": "Vuln\u00e9rabilit\u00e9 dans les produits F5",
      "vendor_advisories": [
        {
          "published_at": "2024-11-06",
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000148232",
          "url": "https://my.f5.com/manage/s/article/K000148232"
        }
      ]
    }

    CERTFR-2023-AVI-0837

    Vulnerability from certfr_avis - Published: 2023-10-12 - Updated: 2023-10-12

    De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    F5 NGINX NGINX OSS versions 1.9.5 à 1.25.2
    F5 BIG-IP BIG-IP (tous modules) versions 16.1.x antérieures à 16.1.4.1 avec le correctif de sécurité Hotfix-BIGIP-16.1.4.1.0.13.5-ENG
    F5 BIG-IQ BIG-IQ Centralized Management versions 8.0.0 à 8.3.0 antérieures à 8.3.0 avec le correctif Hotfix-BIG-IQ-8.3.0.0.12.118-ENG
    F5 BIG-IP Next BIG-IP Next SPK versions 1.5.0 à 1.8.2
    F5 BIG-IP BIG-IP (APM) versions 16.1.0 à 16.1.3 antérieures à 16.1.4
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 3.0.0 à 3.3.0
    F5 BIG-IP BIG-IP (Advanced WAF/ASM) versions 16.1.x antérieures à 16.1.4
    F5 NGINX Plus NGINX Plus verions R25 à R30 antérieures à R30 P1
    F5 BIG-IP BIG-IP (DNS, LTM avec le license DNS Services activée) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.9
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 2.0.0 à 2.4.2
    F5 BIG-IP BIG-IP (DNS, LTM avec le license DNS Services activée) versions 16.1.x antérieures à 16.1.4
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 1.12.2 à 1.12.5
    F5 BIG-IP Next BIG-IP Next CNF versions 1.1.0 à 1.1.1
    F5 NGINX NGINX App Protect WAF versions 3.3.0 à 3.12.2 et 4.x antérieures à 4.2.0
    F5 BIG-IP BIG-IP (Advanced WAF/ASM) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.9
    F5 N/A APM Clients versions 7.2.3.x, 7.2.4.x antérieures à 7.2.4.5
    F5 BIG-IP Next BIG-IP Next (tous modules) version 20.0.1
    F5 BIG-IP BIG-IP (tous modules) versions 13.1.x, 14.1.x, 15.1.x antérieures à 15.1.10.2
    F5 BIG-IP BIG-IP (tous modules) versions 17.1.x antérieures à 17.1.0.3 avec le correctif de sécurité Hotfix-BIGIP-17.1.0.3.0.23.4-ENG
    F5 BIG-IP BIG-IP (APM) versions 14.1.x, 15.1.x antérieures à 15.1.9
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NGINX OSS versions 1.9.5 \u00e0 1.25.2",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4.1 avec le correctif de s\u00e9curit\u00e9 Hotfix-BIGIP-16.1.4.1.0.13.5-ENG",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IQ Centralized Management versions 8.0.0 \u00e0 8.3.0 ant\u00e9rieures \u00e0 8.3.0 avec le correctif Hotfix-BIG-IQ-8.3.0.0.12.118-ENG",
          "product": {
            "name": "BIG-IQ",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP Next SPK versions 1.5.0 \u00e0 1.8.2",
          "product": {
            "name": "BIG-IP Next",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (APM) versions 16.1.0 \u00e0 16.1.3 ant\u00e9rieures \u00e0 16.1.4",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 3.0.0 \u00e0 3.3.0",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (Advanced WAF/ASM) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Plus verions R25 \u00e0 R30 ant\u00e9rieures \u00e0 R30 P1",
          "product": {
            "name": "NGINX Plus",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (DNS, LTM avec le license DNS Services activ\u00e9e) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 2.0.0 \u00e0 2.4.2",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (DNS, LTM avec le license DNS Services activ\u00e9e) versions 16.1.x ant\u00e9rieures \u00e0 16.1.4",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 1.12.2 \u00e0 1.12.5",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP Next CNF versions 1.1.0 \u00e0 1.1.1",
          "product": {
            "name": "BIG-IP Next",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX App Protect WAF versions 3.3.0 \u00e0 3.12.2 et 4.x ant\u00e9rieures \u00e0 4.2.0",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (Advanced WAF/ASM) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "APM Clients versions 7.2.3.x, 7.2.4.x ant\u00e9rieures \u00e0 7.2.4.5",
          "product": {
            "name": "N/A",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP Next (tous modules) version 20.0.1",
          "product": {
            "name": "BIG-IP Next",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 13.1.x, 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.10.2",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 17.1.x ant\u00e9rieures \u00e0 17.1.0.3 avec le correctif de s\u00e9curit\u00e9 Hotfix-BIGIP-17.1.0.3.0.23.4-ENG",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (APM) versions 14.1.x, 15.1.x ant\u00e9rieures \u00e0 15.1.9",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2023-40542",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-40542"
        },
        {
          "name": "CVE-2023-5450",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-5450"
        },
        {
          "name": "CVE-2023-41373",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41373"
        },
        {
          "name": "CVE-2023-43746",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-43746"
        },
        {
          "name": "CVE-2023-40537",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-40537"
        },
        {
          "name": "CVE-2023-44487",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-44487"
        },
        {
          "name": "CVE-2023-41085",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41085"
        },
        {
          "name": "CVE-2023-41253",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41253"
        },
        {
          "name": "CVE-2023-42768",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-42768"
        },
        {
          "name": "CVE-2023-43611",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-43611"
        },
        {
          "name": "CVE-2023-45226",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45226"
        },
        {
          "name": "CVE-2023-45219",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-45219"
        },
        {
          "name": "CVE-2023-41964",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-41964"
        },
        {
          "name": "CVE-2023-39447",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-39447"
        },
        {
          "name": "CVE-2023-40534",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-40534"
        },
        {
          "name": "CVE-2023-43485",
          "url": "https://www.cve.org/CVERecord?id=CVE-2023-43485"
        }
      ],
      "initial_release_date": "2023-10-12T00:00:00",
      "last_revision_date": "2023-10-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2023-AVI-0837",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2023-10-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K000137053 du 10 octobre 2023",
          "url": "https://my.f5.com/manage/s/article/K000137053"
        }
      ]
    }

    CERTFR-2022-AVI-937

    Vulnerability from certfr_avis - Published: 2022-10-20 - Updated: 2022-10-20

    De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    F5 BIG-IP BIG-IP (all modules) versions 14.1.x antérieures à 14.1.5.2
    F5 NGINX Plus NGINX Plus R26 P1 ou R27 P1
    F5 BIG-IP BIG-IP (all modules) versions 17.0.x antérieures à 17.0.0.1
    F5 NGINX Ingress Controller NGINX Ingress Controller toutes versions
    F5 BIG-IP BIG-IP (all modules) versions 16.1.x antérieures à 16.1.3.2
    F5 NGINX NGINX App Protect WAF versions antérieures à 3.12
    F5 BIG-IP BIG-IP (all modules) versions 15.1.x antérieures à 15.1.7
    F5 NGINX NGINX Open Source versions 1.22.x antérieures à 1.22.1
    F5 BIG-IP BIG-IP (all modules) versions 13.1.x antérieures à 13.1.5.1
    F5 NGINX NGINX Open Source versions 1.23.x antérieures à 1.23.2
    F5 NGINX NGINX Open Source Subscription R1 P1 ou R2 P1

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "BIG-IP (all modules) versions 14.1.x ant\u00e9rieures \u00e0 14.1.5.2",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Plus R26 P1 ou R27 P1",
          "product": {
            "name": "NGINX Plus",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (all modules) versions 17.0.x ant\u00e9rieures \u00e0 17.0.0.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller toutes versions",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (all modules) versions 16.1.x ant\u00e9rieures \u00e0 16.1.3.2",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX App Protect WAF versions ant\u00e9rieures \u00e0 3.12",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (all modules) versions 15.1.x ant\u00e9rieures \u00e0 15.1.7",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Open Source versions 1.22.x ant\u00e9rieures \u00e0 1.22.1",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (all modules) versions 13.1.x ant\u00e9rieures \u00e0 13.1.5.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Open Source versions 1.23.x ant\u00e9rieures \u00e0 1.23.2",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Open Source Subscription R1 P1 ou R2 P1",
          "product": {
            "name": "NGINX",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-36795",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-36795"
        },
        {
          "name": "CVE-2022-41770",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41770"
        },
        {
          "name": "CVE-2022-41787",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41787"
        },
        {
          "name": "CVE-2022-41691",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41691"
        },
        {
          "name": "CVE-2022-41813",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41813"
        },
        {
          "name": "CVE-2022-41694",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41694"
        },
        {
          "name": "CVE-2022-41741",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41741"
        },
        {
          "name": "CVE-2022-41742",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41742"
        },
        {
          "name": "CVE-2022-41836",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41836"
        },
        {
          "name": "CVE-2022-41624",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41624"
        },
        {
          "name": "CVE-2022-41833",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41833"
        },
        {
          "name": "CVE-2022-41806",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41806"
        },
        {
          "name": "CVE-2022-41617",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41617"
        },
        {
          "name": "CVE-2022-41832",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41832"
        },
        {
          "name": "CVE-2022-41983",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41983"
        },
        {
          "name": "CVE-2022-41743",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-41743"
        }
      ],
      "initial_release_date": "2022-10-20T00:00:00",
      "last_revision_date": "2022-10-20T00:00:00",
      "links": [
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K11830089 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K11830089"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K02694732 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K02694732"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K30425568 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K30425568"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K28112382 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K28112382"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K70569537 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K70569537"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K01112063 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K01112063"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K81926432 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K81926432"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K27155546 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K27155546"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K10347453 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K10347453"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K49237345 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K49237345"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K22505850 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K22505850"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K24823443 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K24823443"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K47204506 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K47204506"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K31523465 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K31523465"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K52494562 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K52494562"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K43024307 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K43024307"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K93723284 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K93723284"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K00721320 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K00721320"
        },
        {
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K04712583 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K04712583"
        }
      ],
      "reference": "CERTFR-2022-AVI-937",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-10-20T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net une atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K76934290 du 19 octobre 2022",
          "url": "https://support.f5.com/csp/article/K76934290"
        }
      ]
    }

    CERTFR-2022-AVI-704

    Vulnerability from certfr_avis - Published: 2022-08-04 - Updated: 2022-08-04

    De multiples vulnérabilités ont été découvertes dans les produits F5. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    F5 BIG-IP BIG-IP (tous modules) versions 16.x antérieures à 16.1.3.1
    F5 BIG-IP BIG-IP (tous modules) versions 17.x antérieures à 17.0.0.1
    F5 BIG-IP BIG-IP (tous modules) versions 15.x antérieures à 15.1.6.1
    F5 NGINX Instance Manager NGINX Instance Manager versions 2.x antérieures à 2.3.1
    F5 BIG-IQ BIG-IQ Centralized Management versions 8.x antérieures à 8.2.0
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 2.x antérieures à 2.3.0
    F5 BIG-IP BIG-IP (tous modules) versions 14.x antérieures à 14.1.5.1
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "BIG-IP (tous modules) versions 16.x ant\u00e9rieures \u00e0 16.1.3.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 17.x ant\u00e9rieures \u00e0 17.0.0.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 15.x ant\u00e9rieures \u00e0 15.1.6.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Instance Manager versions 2.x ant\u00e9rieures \u00e0 2.3.1",
          "product": {
            "name": "NGINX Instance Manager",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IQ Centralized Management versions 8.x ant\u00e9rieures \u00e0 8.2.0",
          "product": {
            "name": "BIG-IQ",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 2.x ant\u00e9rieures \u00e0 2.3.0",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "BIG-IP (tous modules) versions 14.x ant\u00e9rieures \u00e0 14.1.5.1",
          "product": {
            "name": "BIG-IP",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2022-31473",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-31473"
        },
        {
          "name": "CVE-2022-35240",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35240"
        },
        {
          "name": "CVE-2022-33203",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-33203"
        },
        {
          "name": "CVE-2022-30535",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-30535"
        },
        {
          "name": "CVE-2022-35241",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35241"
        },
        {
          "name": "CVE-2022-35243",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35243"
        },
        {
          "name": "CVE-2022-34865",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34865"
        },
        {
          "name": "CVE-2022-35236",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35236"
        },
        {
          "name": "CVE-2022-34862",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34862"
        },
        {
          "name": "CVE-2022-35728",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35728"
        },
        {
          "name": "CVE-2022-34651",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34651"
        },
        {
          "name": "CVE-2022-35272",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35272"
        },
        {
          "name": "CVE-2022-34655",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34655"
        },
        {
          "name": "CVE-2022-32455",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-32455"
        },
        {
          "name": "CVE-2022-35245",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35245"
        },
        {
          "name": "CVE-2022-33947",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-33947"
        },
        {
          "name": "CVE-2022-35735",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-35735"
        },
        {
          "name": "CVE-2022-34844",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34844"
        },
        {
          "name": "CVE-2022-33968",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-33968"
        },
        {
          "name": "CVE-2022-34851",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-34851"
        },
        {
          "name": "CVE-2022-33962",
          "url": "https://www.cve.org/CVERecord?id=CVE-2022-33962"
        }
      ],
      "initial_release_date": "2022-08-04T00:00:00",
      "last_revision_date": "2022-08-04T00:00:00",
      "links": [],
      "reference": "CERTFR-2022-AVI-704",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2022-08-04T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "D\u00e9ni de service \u00e0 distance"
        },
        {
          "description": "Ex\u00e9cution de code arbitraire \u00e0 distance"
        },
        {
          "description": "Atteinte \u00e0 l\u0027int\u00e9grit\u00e9 des donn\u00e9es"
        },
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        },
        {
          "description": "\u00c9l\u00e9vation de privil\u00e8ges"
        }
      ],
      "summary": "De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans les produits F5.\nCertaines d\u0027entre elles permettent \u00e0 un attaquant de provoquer une\nex\u00e9cution de code arbitraire \u00e0 distance, un d\u00e9ni de service \u00e0 distance\net un contournement de la politique de s\u00e9curit\u00e9.\n",
      "title": "Multiples vuln\u00e9rabilit\u00e9s dans les produits F5",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K14649763 du 03 ao\u00fbt 2022",
          "url": "https://support.f5.com/csp/article/K14649763"
        }
      ]
    }

    CERTFR-2021-AVI-871

    Vulnerability from certfr_avis - Published: 2021-11-12 - Updated: 2021-11-12

    Une vulnérabilité a été découverte dans F5 NGINX Ingress Controller. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité et une atteinte à la confidentialité des données.

    Solution

    Se référer au bulletin de sécurité de l'éditeur pour l'obtention des correctifs (cf. section Documentation).

    None
    Impacted products
    Vendor Product Description
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 1.x antérieures à 1.12.2
    F5 NGINX Ingress Controller NGINX Ingress Controller versions 2.x antérieures à 2.0.2
    References

    Show details on source website

    {
      "$ref": "https://www.cert.ssi.gouv.fr/openapi.json",
      "affected_systems": [
        {
          "description": "NGINX Ingress Controller versions 1.x ant\u00e9rieures \u00e0 1.12.2",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        },
        {
          "description": "NGINX Ingress Controller versions 2.x ant\u00e9rieures \u00e0 2.0.2",
          "product": {
            "name": "NGINX Ingress Controller",
            "vendor": {
              "name": "F5",
              "scada": false
            }
          }
        }
      ],
      "affected_systems_content": null,
      "content": "## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l\u0027\u00e9diteur pour l\u0027obtention des\ncorrectifs (cf. section Documentation).\n",
      "cves": [
        {
          "name": "CVE-2021-23055",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-23055"
        }
      ],
      "initial_release_date": "2021-11-12T00:00:00",
      "last_revision_date": "2021-11-12T00:00:00",
      "links": [],
      "reference": "CERTFR-2021-AVI-871",
      "revisions": [
        {
          "description": "Version initiale",
          "revision_date": "2021-11-12T00:00:00.000000"
        }
      ],
      "risks": [
        {
          "description": "Contournement de la politique de s\u00e9curit\u00e9"
        },
        {
          "description": "Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"
        }
      ],
      "summary": "Une vuln\u00e9rabilit\u00e9 a \u00e9t\u00e9 d\u00e9couverte dans F5 NGINX Ingress Controller.\nElle permet \u00e0 un attaquant de provoquer un contournement de la politique\nde s\u00e9curit\u00e9 et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n",
      "title": "Vuln\u00e9rabilit\u00e9 dans F5 NGINX Ingress Controller",
      "vendor_advisories": [
        {
          "published_at": null,
          "title": "Bulletin de s\u00e9curit\u00e9 F5 K01051452 du 11 novembre 2021",
          "url": "https://support.f5.com/csp/article/K01051452"
        }
      ]
    }

    CVE-2026-77180 (GCVE-0-2026-77180)

    Vulnerability from nvd – Published: 2026-09-02 15:40 – Updated: 2026-09-03 03:56
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 00:00 UTC
    CWE
    • CWE-76 - Improper Neutralization of Equivalent Special Elements
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.6.0 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r5 (custom)
    Create a notification for this product.
    Date Public
    2026-09-02 14:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77180",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T03:56:37.740Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Ingress Annotations"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.6.0",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r5",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "F5 acknowledges kodareef5 for bringing this issue to our attention and following the highest standards of coordinated disclosure."
            }
          ],
          "datePublic": "2026-09-02T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives.\u003c/span\u003e \u003cbr\u003e\u003cbr\u003eImpact:\u003cbr\u003eAn authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. \n\nImpact:\nAn authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-76",
                  "description": "CWE-76 Improper Neutralization of Equivalent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T15:40:54.771Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000162601"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cul\u003e\u003cli\u003eRestrict Kubernetes Role-based Access Control (RBAC) create, update, and patch permissions on VirtualServer, VirtualServerRoute, Policy, DosProtectedResource, and Ingress resources to trusted cluster administrators only.\u003c/li\u003e\u003cli\u003eDeploy an admission policy (Kyverno, OPA Gatekeeper, or ValidatingAdmissionPolicy) that rejects resources containing special characters in user-controlled fields.\u003c/li\u003e\u003c/ul\u003e"
                }
              ],
              "value": "*  Restrict Kubernetes Role-based Access Control (RBAC) create, update, and patch permissions on VirtualServer, VirtualServerRoute, Policy, DosProtectedResource, and Ingress resources to trusted cluster administrators only.\n  *  Deploy an admission policy (Kyverno, OPA Gatekeeper, or ValidatingAdmissionPolicy) that rejects resources containing special characters in user-controlled fields."
            }
          ],
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-77180",
        "datePublished": "2026-09-02T15:40:54.771Z",
        "dateReserved": "2026-08-20T15:36:41.188Z",
        "dateUpdated": "2026-09-03T03:56:37.740Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-55723 (GCVE-0-2026-55723)

    Vulnerability from nvd – Published: 2026-07-15 14:33 – Updated: 2026-07-16 03:55
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-15 00:00 UTC
    CWE
    • CWE-76 - Improper Neutralization of Equivalent Special Elements
    References
    URL Tags
    https://my.f5.com/manage/s/article/K000161800 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.5.2 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r3 (custom)
    Create a notification for this product.
    Date Public
    2026-07-15 14:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-55723",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-15T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-16T03:55:31.898Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Custom Resource Definitions",
                "Ingress Annotations"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.5.2",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r3",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "F5"
            }
          ],
          "datePublic": "2026-07-15T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives.\u003c/span\u003e \u003cbr\u003e\u003cbr\u003eImpact:\u003cbr\u003eAn authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. \n\nImpact:\nAn authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-76",
                  "description": "CWE-76 Improper Neutralization of Equivalent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-15T14:33:44.806Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://my.f5.com/manage/s/article/K000161800"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-55723",
        "datePublished": "2026-07-15T14:33:44.806Z",
        "dateReserved": "2026-06-17T23:45:50.277Z",
        "dateUpdated": "2026-07-16T03:55:31.898Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52865 (GCVE-0-2026-52865)

    Vulnerability from nvd – Published: 2026-07-15 14:33 – Updated: 2026-07-15 15:36
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-15 15:36 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    References
    URL Tags
    https://my.f5.com/manage/s/article/K000161834 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.5.2 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r3 (custom)
    Create a notification for this product.
    Date Public
    2026-07-15 14:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52865",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-15T15:36:49.413847Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T15:36:57.172Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Ingress",
                "TransportServer"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.5.2",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r3",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "F5"
            }
          ],
          "datePublic": "2026-07-15T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate.\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e \u003cbr\u003e\u003cbr\u003e\n\nImpact:\u003cbr\u003eThe NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. \n\n\n\nImpact:\nThe NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-15T14:33:45.155Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://my.f5.com/manage/s/article/K000161834"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-52865",
        "datePublished": "2026-07-15T14:33:45.155Z",
        "dateReserved": "2026-06-17T23:45:50.281Z",
        "dateUpdated": "2026-07-15T15:36:57.172Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14727 (GCVE-0-2025-14727)

    Vulnerability from nvd – Published: 2025-12-17 15:48 – Updated: 2026-02-26 16:07 X_F5
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 04:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.3.0 , < 5.3.1 (custom)
    Unaffected: 5.2.0 , < * (custom)
    Unaffected: 5.1.0 , < * (custom)
    Unaffected: 5.0.0 , < * (custom)
    Unaffected: 4.0.0 , < * (custom)
    Unaffected: 3.0.0 , < * (custom)
    Create a notification for this product.
    Date Public
    2025-12-17 15:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14727",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T04:55:23.427345Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T16:07:31.198Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.3.1",
                  "status": "affected",
                  "version": "5.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "4.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "3.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "F5 acknowledges Ricardo Katz of Red Hat for bringing this issue to our attention and following the highest standards of coordinated disclosure."
            }
          ],
          "datePublic": "2025-12-17T15:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA vulnerability exists in NGINX Ingress Controller\u0027s \u003c/span\u003e\u003cstrong\u003enginx.org/rewrite-target\u003c/strong\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;annotation validation.\u003c/span\u003e \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "A vulnerability exists in NGINX Ingress Controller\u0027s nginx.org/rewrite-target\u00a0annotation validation. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-17T15:48:22.193Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000158176"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_F5"
          ],
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2025-14727",
        "datePublished": "2025-12-17T15:48:22.193Z",
        "dateReserved": "2025-12-15T16:22:28.776Z",
        "dateUpdated": "2026-02-26T16:07:31.198Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-10318 (GCVE-0-2024-10318)

    Vulnerability from nvd – Published: 2024-11-06 16:48 – Updated: 2024-11-06 16:57
    VLAI
    Title
    NGINX OpenID Connect Vulnerability
    Summary
    A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-06 16:57 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    F5 NGINX OpenID Connect Affected: fa1ad160e2637d1d583611124478039170d726ab , < 133504f4fd9f72f3e36668f9f2f3d32a86fcb269 (git)
    Create a notification for this product.
    F5 NGINX Instance Manager Affected: 2.5.0 , < 2.17.4 (semver)
    Create a notification for this product.
    F5 NGINX API Connectivity Manager Affected: 1.0.0 , < 1.9.3 (semver)
    Create a notification for this product.
    F5 NGINX Ingress Controller Affected: 1.0.0 , < 3.7.1 (semver)
    Create a notification for this product.
    Date Public
    2024-11-06 15:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10318",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-06T16:57:19.535215Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T16:57:40.692Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "NGINX OpenID Connect",
              "repo": "https://github.com/nginxinc/nginx-openid-connect/",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "133504f4fd9f72f3e36668f9f2f3d32a86fcb269",
                  "status": "affected",
                  "version": "fa1ad160e2637d1d583611124478039170d726ab",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX Instance Manager",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "2.17.4",
                  "status": "affected",
                  "version": "2.5.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX API Connectivity Manager",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "1.9.3",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "3.7.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Christian August Holm Hansen of Binary Security AS"
            }
          ],
          "datePublic": "2024-11-06T15:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim\u0027s session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim\u0027s session.\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim\u0027s session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim\u0027s session."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-384",
                  "description": "CWE-384 Session Fixation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-06T16:48:56.128Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000148232"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "NGINX OpenID Connect Vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2024-10318",
        "datePublished": "2024-11-06T16:48:56.128Z",
        "dateReserved": "2024-10-23T19:34:33.203Z",
        "dateUpdated": "2024-11-06T16:57:40.692Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30535 (GCVE-0-2022-30535)

    Vulnerability from nvd – Published: 2022-08-04 17:45 – Updated: 2024-09-16 20:07
    VLAI
    Title
    NGINX Ingress Controller vulnerability CVE-2022-30535
    Summary
    In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 2.x , < 2.3.0 (custom)
    Affected: 1.0.0 , < 1.x* (custom)
    Create a notification for this product.
    Date Public
    2022-08-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T06:48:36.417Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.f5.com/csp/article/K52125139"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "2.3.0",
                  "status": "affected",
                  "version": "2.x",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.x*",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-08-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-04T17:45:41.000Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.f5.com/csp/article/K52125139"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability CVE-2022-30535",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "f5sirt@f5.com",
              "DATE_PUBLIC": "2022-08-03T14:00:00.000Z",
              "ID": "CVE-2022-30535",
              "STATE": "PUBLIC",
              "TITLE": "NGINX Ingress Controller vulnerability CVE-2022-30535"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "NGINX Ingress Controller",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "2.x",
                                "version_value": "2.3.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_name": "1.x",
                                "version_value": "1.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "F5"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-20 Improper Input Validation"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.f5.com/csp/article/K52125139",
                  "refsource": "MISC",
                  "url": "https://support.f5.com/csp/article/K52125139"
                }
              ]
            },
            "source": {
              "discovery": "INTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2022-30535",
        "datePublished": "2022-08-04T17:45:41.852Z",
        "dateReserved": "2022-07-19T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:07:20.068Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2026-77180 (GCVE-0-2026-77180)

    Vulnerability from cvelistv5 – Published: 2026-09-02 15:40 – Updated: 2026-09-03 03:56
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-09-02 00:00 UTC
    CWE
    • CWE-76 - Improper Neutralization of Equivalent Special Elements
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.6.0 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r5 (custom)
    Create a notification for this product.
    Date Public
    2026-09-02 14:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-77180",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-09-02T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-09-03T03:56:37.740Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Ingress Annotations"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.6.0",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r5",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "F5 acknowledges kodareef5 for bringing this issue to our attention and following the highest standards of coordinated disclosure."
            }
          ],
          "datePublic": "2026-09-02T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives.\u003c/span\u003e \u003cbr\u003e\u003cbr\u003eImpact:\u003cbr\u003eAn authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. \n\nImpact:\nAn authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-76",
                  "description": "CWE-76 Improper Neutralization of Equivalent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-09-02T15:40:54.771Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000162601"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "workarounds": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cul\u003e\u003cli\u003eRestrict Kubernetes Role-based Access Control (RBAC) create, update, and patch permissions on VirtualServer, VirtualServerRoute, Policy, DosProtectedResource, and Ingress resources to trusted cluster administrators only.\u003c/li\u003e\u003cli\u003eDeploy an admission policy (Kyverno, OPA Gatekeeper, or ValidatingAdmissionPolicy) that rejects resources containing special characters in user-controlled fields.\u003c/li\u003e\u003c/ul\u003e"
                }
              ],
              "value": "*  Restrict Kubernetes Role-based Access Control (RBAC) create, update, and patch permissions on VirtualServer, VirtualServerRoute, Policy, DosProtectedResource, and Ingress resources to trusted cluster administrators only.\n  *  Deploy an admission policy (Kyverno, OPA Gatekeeper, or ValidatingAdmissionPolicy) that rejects resources containing special characters in user-controlled fields."
            }
          ],
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-77180",
        "datePublished": "2026-09-02T15:40:54.771Z",
        "dateReserved": "2026-08-20T15:36:41.188Z",
        "dateUpdated": "2026-09-03T03:56:37.740Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-52865 (GCVE-0-2026-52865)

    Vulnerability from cvelistv5 – Published: 2026-07-15 14:33 – Updated: 2026-07-15 15:36
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-15 15:36 UTC
    CWE
    • CWE-476 - NULL Pointer Dereference
    References
    URL Tags
    https://my.f5.com/manage/s/article/K000161834 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.5.2 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r3 (custom)
    Create a notification for this product.
    Date Public
    2026-07-15 14:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-52865",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-15T15:36:49.413847Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-15T15:36:57.172Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Ingress",
                "TransportServer"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.5.2",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r3",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "F5"
            }
          ],
          "datePublic": "2026-07-15T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate.\u003c/span\u003e\u003c/span\u003e\u003c/span\u003e \u003cbr\u003e\u003cbr\u003e\n\nImpact:\u003cbr\u003eThe NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. \n\n\n\nImpact:\nThe NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "HIGH",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "NONE",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 7.1,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "NONE",
                "vulnIntegrityImpact": "NONE",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-476",
                  "description": "CWE-476 NULL Pointer Dereference",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-15T14:33:45.155Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://my.f5.com/manage/s/article/K000161834"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-52865",
        "datePublished": "2026-07-15T14:33:45.155Z",
        "dateReserved": "2026-06-17T23:45:50.281Z",
        "dateUpdated": "2026-07-15T15:36:57.172Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-55723 (GCVE-0-2026-55723)

    Vulnerability from cvelistv5 – Published: 2026-07-15 14:33 – Updated: 2026-07-16 03:55
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-15 00:00 UTC
    CWE
    • CWE-76 - Improper Neutralization of Equivalent Special Elements
    References
    URL Tags
    https://my.f5.com/manage/s/article/K000161800 vendor-advisorypatch
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.0.0 , < 5.5.2 (custom)
    Affected: 2026-lts-r1 , < 2026-lts-r3 (custom)
    Create a notification for this product.
    Date Public
    2026-07-15 14:00
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-55723",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-15T00:00:00+00:00",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-16T03:55:31.898Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "modules": [
                "Custom Resource Definitions",
                "Ingress Annotations"
              ],
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.5.2",
                  "status": "affected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "2026-lts-r3",
                  "status": "affected",
                  "version": "2026-lts-r1",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "F5"
            }
          ],
          "datePublic": "2026-07-15T14:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eWhen NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives.\u003c/span\u003e \u003cbr\u003e\u003cbr\u003eImpact:\u003cbr\u003eAn authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\u003cbr\u003e\u003cbr\u003eNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. \n\nImpact:\nAn authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-76",
                  "description": "CWE-76 Improper Neutralization of Equivalent Special Elements",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-15T14:33:44.806Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory",
                "patch"
              ],
              "url": "https://my.f5.com/manage/s/article/K000161800"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2026-55723",
        "datePublished": "2026-07-15T14:33:44.806Z",
        "dateReserved": "2026-06-17T23:45:50.277Z",
        "dateUpdated": "2026-07-16T03:55:31.898Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2025-14727 (GCVE-0-2025-14727)

    Vulnerability from cvelistv5 – Published: 2025-12-17 15:48 – Updated: 2026-02-26 16:07 X_F5
    VLAI
    Title
    NGINX Ingress Controller vulnerability
    Summary
    A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2025-12-18 04:55 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 5.3.0 , < 5.3.1 (custom)
    Unaffected: 5.2.0 , < * (custom)
    Unaffected: 5.1.0 , < * (custom)
    Unaffected: 5.0.0 , < * (custom)
    Unaffected: 4.0.0 , < * (custom)
    Unaffected: 3.0.0 , < * (custom)
    Create a notification for this product.
    Date Public
    2025-12-17 15:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2025-14727",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2025-12-18T04:55:23.427345Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-02-26T16:07:31.198Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "5.3.1",
                  "status": "affected",
                  "version": "5.3.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.2.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.1.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "5.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "4.0.0",
                  "versionType": "custom"
                },
                {
                  "lessThan": "*",
                  "status": "unaffected",
                  "version": "3.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "reporter",
              "value": "F5 acknowledges Ricardo Katz of Red Hat for bringing this issue to our attention and following the highest standards of coordinated disclosure."
            }
          ],
          "datePublic": "2025-12-17T15:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA vulnerability exists in NGINX Ingress Controller\u0027s \u003c/span\u003e\u003cstrong\u003enginx.org/rewrite-target\u003c/strong\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;annotation validation.\u003c/span\u003e \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ],
              "value": "A vulnerability exists in NGINX Ingress Controller\u0027s nginx.org/rewrite-target\u00a0annotation validation. \n\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "LOW",
                "baseScore": 8.3,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22 Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2025-12-17T15:48:22.193Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000158176"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "tags": [
            "x_F5"
          ],
          "title": "NGINX Ingress Controller vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2025-14727",
        "datePublished": "2025-12-17T15:48:22.193Z",
        "dateReserved": "2025-12-15T16:22:28.776Z",
        "dateUpdated": "2026-02-26T16:07:31.198Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2024-10318 (GCVE-0-2024-10318)

    Vulnerability from cvelistv5 – Published: 2024-11-06 16:48 – Updated: 2024-11-06 16:57
    VLAI
    Title
    NGINX OpenID Connect Vulnerability
    Summary
    A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim's session.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2024-11-06 16:57 UTC
    CWE
    References
    Impacted products
    Vendor Product Version
    F5 NGINX OpenID Connect Affected: fa1ad160e2637d1d583611124478039170d726ab , < 133504f4fd9f72f3e36668f9f2f3d32a86fcb269 (git)
    Create a notification for this product.
    F5 NGINX Instance Manager Affected: 2.5.0 , < 2.17.4 (semver)
    Create a notification for this product.
    F5 NGINX API Connectivity Manager Affected: 1.0.0 , < 1.9.3 (semver)
    Create a notification for this product.
    F5 NGINX Ingress Controller Affected: 1.0.0 , < 3.7.1 (semver)
    Create a notification for this product.
    Date Public
    2024-11-06 15:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2024-10318",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2024-11-06T16:57:19.535215Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2024-11-06T16:57:40.692Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unknown",
              "product": "NGINX OpenID Connect",
              "repo": "https://github.com/nginxinc/nginx-openid-connect/",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "133504f4fd9f72f3e36668f9f2f3d32a86fcb269",
                  "status": "affected",
                  "version": "fa1ad160e2637d1d583611124478039170d726ab",
                  "versionType": "git"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX Instance Manager",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "2.17.4",
                  "status": "affected",
                  "version": "2.5.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX API Connectivity Manager",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "1.9.3",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            },
            {
              "defaultStatus": "unaffected",
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "3.7.1",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "Christian August Holm Hansen of Binary Security AS"
            }
          ],
          "datePublic": "2024-11-06T15:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "supportingMedia": [
                {
                  "base64": false,
                  "type": "text/html",
                  "value": "\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003eA session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim\u0027s session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim\u0027s session.\u003c/span\u003e\u003cspan style=\"background-color: rgb(255, 255, 255);\"\u003e\u0026nbsp;\u003c/span\u003e\u003cbr\u003e"
                }
              ],
              "value": "A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim\u0027s session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacker-controlled account, leading to potential misuse of the victim\u0027s session."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.4,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "LOW",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N",
                "version": "3.1"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            },
            {
              "cvssV4_0": {
                "Automatable": "NOT_DEFINED",
                "Recovery": "NOT_DEFINED",
                "Safety": "NOT_DEFINED",
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 5.1,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "providerUrgency": "NOT_DEFINED",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "ACTIVE",
                "valueDensity": "NOT_DEFINED",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "NONE",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "LOW",
                "vulnerabilityResponseEffort": "NOT_DEFINED"
              },
              "format": "CVSS",
              "scenarios": [
                {
                  "lang": "en",
                  "value": "GENERAL"
                }
              ]
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-384",
                  "description": "CWE-384 Session Fixation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2024-11-06T16:48:56.128Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "vendor-advisory"
              ],
              "url": "https://my.f5.com/manage/s/article/K000148232"
            }
          ],
          "source": {
            "discovery": "EXTERNAL"
          },
          "title": "NGINX OpenID Connect Vulnerability",
          "x_generator": {
            "engine": "F5 SIRTBot v1.0"
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2024-10318",
        "datePublished": "2024-11-06T16:48:56.128Z",
        "dateReserved": "2024-10-23T19:34:33.203Z",
        "dateUpdated": "2024-11-06T16:57:40.692Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }

    CVE-2022-30535 (GCVE-0-2022-30535)

    Vulnerability from cvelistv5 – Published: 2022-08-04 17:45 – Updated: 2024-09-16 20:07
    VLAI
    Title
    NGINX Ingress Controller vulnerability CVE-2022-30535
    Summary
    In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
    CWE
    • CWE-20 - Improper Input Validation
    References
    Impacted products
    Vendor Product Version
    F5 NGINX Ingress Controller Affected: 2.x , < 2.3.0 (custom)
    Affected: 1.0.0 , < 1.x* (custom)
    Create a notification for this product.
    Date Public
    2022-08-03 00:00
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "providerMetadata": {
              "dateUpdated": "2024-08-03T06:48:36.417Z",
              "orgId": "af854a3a-2127-422b-91ae-364da2661108",
              "shortName": "CVE"
            },
            "references": [
              {
                "tags": [
                  "x_refsource_MISC",
                  "x_transferred"
                ],
                "url": "https://support.f5.com/csp/article/K52125139"
              }
            ],
            "title": "CVE Program Container"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "NGINX Ingress Controller",
              "vendor": "F5",
              "versions": [
                {
                  "lessThan": "2.3.0",
                  "status": "affected",
                  "version": "2.x",
                  "versionType": "custom"
                },
                {
                  "lessThan": "1.x*",
                  "status": "affected",
                  "version": "1.0.0",
                  "versionType": "custom"
                }
              ]
            }
          ],
          "datePublic": "2022-08-03T00:00:00.000Z",
          "descriptions": [
            {
              "lang": "en",
              "value": "In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-20",
                  "description": "CWE-20 Improper Input Validation",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2022-08-04T17:45:41.000Z",
            "orgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
            "shortName": "f5"
          },
          "references": [
            {
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://support.f5.com/csp/article/K52125139"
            }
          ],
          "source": {
            "discovery": "INTERNAL"
          },
          "title": "NGINX Ingress Controller vulnerability CVE-2022-30535",
          "x_generator": {
            "engine": "Vulnogram 0.0.9"
          },
          "x_legacyV4Record": {
            "CVE_data_meta": {
              "ASSIGNER": "f5sirt@f5.com",
              "DATE_PUBLIC": "2022-08-03T14:00:00.000Z",
              "ID": "CVE-2022-30535",
              "STATE": "PUBLIC",
              "TITLE": "NGINX Ingress Controller vulnerability CVE-2022-30535"
            },
            "affects": {
              "vendor": {
                "vendor_data": [
                  {
                    "product": {
                      "product_data": [
                        {
                          "product_name": "NGINX Ingress Controller",
                          "version": {
                            "version_data": [
                              {
                                "version_affected": "\u003c",
                                "version_name": "2.x",
                                "version_value": "2.3.0"
                              },
                              {
                                "version_affected": "\u003e=",
                                "version_name": "1.x",
                                "version_value": "1.0.0"
                              }
                            ]
                          }
                        }
                      ]
                    },
                    "vendor_name": "F5"
                  }
                ]
              }
            },
            "data_format": "MITRE",
            "data_type": "CVE",
            "data_version": "4.0",
            "description": {
              "description_data": [
                {
                  "lang": "eng",
                  "value": "In versions 2.x before 2.3.0 and all versions of 1.x, An attacker authorized to create or update ingress objects can obtain the secrets available to the NGINX Ingress Controller. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated."
                }
              ]
            },
            "generator": {
              "engine": "Vulnogram 0.0.9"
            },
            "impact": {
              "cvss": {
                "attackComplexity": "LOW",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 6.5,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "NONE",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
                "version": "3.1"
              }
            },
            "problemtype": {
              "problemtype_data": [
                {
                  "description": [
                    {
                      "lang": "eng",
                      "value": "CWE-20 Improper Input Validation"
                    }
                  ]
                }
              ]
            },
            "references": {
              "reference_data": [
                {
                  "name": "https://support.f5.com/csp/article/K52125139",
                  "refsource": "MISC",
                  "url": "https://support.f5.com/csp/article/K52125139"
                }
              ]
            },
            "source": {
              "discovery": "INTERNAL"
            }
          }
        }
      },
      "cveMetadata": {
        "assignerOrgId": "9dacffd4-cb11-413f-8451-fbbfd4ddc0ab",
        "assignerShortName": "f5",
        "cveId": "CVE-2022-30535",
        "datePublished": "2022-08-04T17:45:41.852Z",
        "dateReserved": "2022-07-19T00:00:00.000Z",
        "dateUpdated": "2024-09-16T20:07:20.068Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.1"
    }