CVE-2026-4342
high
CVSS v3
8.8
VIR risk
8.8
Description
ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
Predictions
Exploit likelihood
92%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Go | k8s.io/ingress-nginx | <0.0.0-20260319175635-5183b7d86137 | 0.0.0-20260319175635-5183b7d86137 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| kubernetes | nginx_ingress_controller | {"endExcluding":"1.13.9"} | 1.13.9 |
| kubernetes | nginx_ingress_controller | 1.15.0 | |
References
- https://github.com/kubernetes/kubernetes/issues/137893
- http://www.openwall.com/lists/oss-security/2026/03/19/9
- https://nvd.nist.gov/vuln/detail/CVE-2026-4342
- https://github.com/kubernetes/ingress-nginx/commit/5183b7d861377a9a2f6d2acaf44f8f6abd5cd0aa
- https://github.com/kubernetes/ingress-nginx
- https://github.com/advisories/GHSA-f53h-mxv9-cp98
CWEs
CWE-20
💬 Discuss CVE-2026-4342 on VIR Community →
Community-verified mitigations for this CVE will appear above when contributors publish them.
Verify integrity in audit chain (admin only). AS-IS.