CVE-2026-52865 - NGINX Ingress Controller vulnerability

CVE Advisories
Post Reply
Starburst-David
Posts: 286
Joined: Wed Feb 11, 2026 8:31 pm

CVE-2026-52865 - NGINX Ingress Controller vulnerability

Post by Starburst-David »

CVE ID: CVE-2026-52865
Published: July 15, 2026
Description: When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Severity: 7.1 | HIGH

More Information:
https://cvefeed.io/vuln/detail/CVE-2026-52865
 

POSTREACT(ions) SUMMARY

Post Reply

Return to “CVE Advisories”