CVE-2026-55723 Details
Description
When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
An injection vulnerability has been identified in the NGINX Ingress Controller, specifically in versions 3.6.0 to 3.7.2, 4.0.0 to 4.0.1, and 5.0.0 to 5.5.1. When the controller is used with Custom Resource Definitions (CRDs) or Ingress annotations, multiple user-controllable fields can be written into the generated NGINX configuration without proper sanitization. This flaw allows an authenticated attacker with permission to create or modify these CRDs or annotations to inject arbitrary NGINX configuration directives. The vulnerability is a control plane issue, with no exposure in the data plane.
To address this vulnerability, users should upgrade to NGINX Ingress Controller version 5.5.2. For versions 4.x and 3.x, no specific update is available, but users are advised to upgrade to a version with the fix. Additionally, it is recommended to restrict Kubernetes Role-based Access Control (RBAC) permissions on Ingress resources to trusted cluster administrators only, and to deploy an admission policy that rejects resources with special characters in user-controlled fields.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://my.f5.com/manage/s/article/K000161800 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-76 | Improper Neutralization of Equivalent Special Elements | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| f5 nginx ingress controller | >= 3.6.0, <= 3.7.2 >= 4.0.0, <= 4.0.1 >= 5.0.0, < 5.5.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 16, 2026 | Initial Analysis | [email protected] |
| Jul 16, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | CVE Modified | CISA-ADP |
| Jul 15, 2026 | New CVE Received | [email protected] |