Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77180— NGINX Ingress Controller vulnerability

Quick assessment

Affected
F5 NGINX Ingress Controller
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

当 NGINX Ingress Controller 配置了 Ingress 注解(annotations)时,NGINX Ingress Controller 的配置生成器中存在注入漏洞。多个用户可控字段未经过清洗(sanitization)就被直接写入生成的 NGINX 配置文件中。拥有创建或修改这些注解权限的已认证攻击者可以构造特定的注解值,从而注入任意的 NGINX 配置指令。 影响: 通过 Kubernetes API 被授予对 NGINX Ingress Controller Ingress 注解具有写

CVSS 8.3 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77180

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NGINX Ingress Controller vulnerability
Source: CVE Program / CVE List V5
Vulnerability Description
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
等价特殊元素的转义处理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
F5 NGINX Ingress Controller 5.0.0 ~ 5.6.0 -

II. Public POCs for CVE-2026-77180

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77180

登录查看更多情报信息。

Other References for CVE-2026-77180 (1)

Same Patch Batch · F5 · 2026-09-02 · 7 CVEs total

CVE-2026-66842 8.8 HIGH BIG-IP and BIG-IQ Configuration utility vulnerability
CVE-2026-18329 8.2 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-78689 8.1 HIGH NGINX ngx_http_js_module vulnerablility
CVE-2026-66362 8.1 HIGH NGF vulnerability
CVE-2026-78222 7.5 HIGH NGINX ngx_http_js_module vulnerability
CVE-2026-63020 3.1 LOW BIG-IP Configuration utility vulnerability

IV. Related Vulnerabilities

V. Comments for CVE-2026-77180

No comments yet


Leave a comment