目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2026-77180— NGINX Ingress Controller 远程代码执行漏洞

一分钟漏洞结论

影响对象
F5 NGINX Ingress Controller
利用判断
尚无明确在野利用证据,仍需结合暴露面评估
建议动作
优先检查厂商安全公告和参考链接中的修复版本;无法立即升级时,限制受影响服务暴露并加强监测。

当 NGINX Ingress Controller 配置了 Ingress 注解(annotations)时,NGINX Ingress Controller 的配置生成器中存在注入漏洞。多个用户可控字段未经过清洗(sanitization)就被直接写入生成的 NGINX 配置文件中。拥有创建或修改这些注解权限的已认证攻击者可以构造特定的注解值,从而注入任意的 NGINX 配置指令。 影响: 通过 Kubernetes API 被授予对 NGINX Ingress Controller Ingress 注解具有写

CVSS 8.3 · High
获取后续新漏洞提醒 登录后订阅

一、 漏洞 CVE-2026-77180 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
NGINX Ingress Controller vulnerability
来源: CVE Program / CVE List V5
Vulnerability Description
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
来源: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
来源: CVE Program / CVE List V5
Vulnerability Type
等价特殊元素的转义处理不恰当
来源: CVE Program / CVE List V5

受影响产品

厂商 产品 影响版本 CPE 订阅
F5 NGINX Ingress Controller 5.0.0 ~ 5.6.0 -

二、漏洞 CVE-2026-77180 的公开POC

# POC 描述 源链接 神龙链接
AI 生成 POC 高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2026-77180 的情报信息

登录查看更多情报信息。

CVE-2026-77180 其他参考 (1)

同批安全公告 · F5 · 2026-09-02 · 共 7 条

CVE-2026-66842 8.8 HIGH F5 BIG-IP 及 BIG-IQ 配置工具漏洞
CVE-2026-18329 8.2 HIGH Nginx ngx_http_js_module 漏洞
CVE-2026-78689 8.1 HIGH Nginx ngx_http_js_module 漏洞
CVE-2026-66362 8.1 HIGH NGF远程代码执行漏洞
CVE-2026-78222 7.5 HIGH Nginx ngx_http_js_module 漏洞
CVE-2026-63020 3.1 LOW F5 BIG-IP 配置工具漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2026-77180

暂无评论


发表评论