F5 nginx ingress controller是美国F5公司开源的一个入口流量控制器。 F5 NGINX Ingress Controller 5.0.0版本至5.5.2之前版本以及2026-lts-r1版本至2026-lts-r3之前版本存在输入验证错误漏洞,该漏洞源于配置生成器在将用户可控字段写入NGINX配置时未进行清理,可能导致经过身份验证的攻击者注入任意NGINX配置指令、创建或删除文件或禁用服务。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| F5 | NGINX Ingress Controller | 5.0.0< 5.5.2 |
affected |
2026-lts-r1< 2026-lts-r3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| F5 | NGINX Ingress Controller | 5.0.0 ~ 5.5.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-60005 | 8.2 HIGH | NGINX ngx_http_slice_module vulnerability |
| CVE-2026-42533 | 8.1 HIGH | NGINX Map directive and Regex matching vulnerability |
| CVE-2026-59762 | 7.5 HIGH | BIG-IP HTTP/2 vulnerability |
| CVE-2026-52865 | 6.5 MEDIUM | NGINX Ingress Controller vulnerability |
| CVE-2026-56434 | 6.5 MEDIUM | NGINX ngx_http_ssi_module vulnerability |
| CVE-2026-60062 | 6.4 MEDIUM | NGINX Agent Vulnerability |
| CVE-2026-60065 | 3.7 LOW | NGINX Plus ngx_stream_mqtt_filter_module vulnerability |
No comments yet