Four ingress-nginx vulnerabilities land shortly before the component retires

The Kubernetes Security Response Committee has published four vulnerabilities in ingress-nginx: CVE-2026-1580, CVE-2026-24512, CVE-2026-24513 and CVE-2026-24514. Two of them, CVE-2026-1580 and CVE-2026-24512, are rated CVSS 8.8 and can lead to arbitrary code execution and disclosure of available Secrets in default configurations. The advisory comes less than three months after the announced retirement of ingress-nginx in March 2026. Affected users should upgrade to v1.13.7, v1.14.3 or later. Partial mitigations exist for some of the flaws.

What this means for your organisation

The ingress controller is the front door to a Kubernetes cluster. If an attacker executes code there, or reads out Secrets, it is not a single application that is compromised but the trust chain between every service in the cluster. That the component is also heading out of maintenance makes this more than a patching job: you face an architecture decision with a deadline, and it belongs in the plan now rather than in March.

Berigo recommends

  • Upgrade ingress-nginx to v1.13.7 or v1.14.3 and verify the version across all clusters, including test and staging.
  • Rotate Secrets that may have been exposed in affected clusters rather than assuming they are safe.
  • Set a decision deadline for which ingress controller replaces it before March 2026, with a named owner and a budget.
  • Review which Secrets the ingress controller actually has access to and narrow it to what is needed.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch