CVE-2026-24514 PUBLISHED

ingress-nginx Admission Controller denial of service

Assigner: kubernetes
Reserved: 23.01.2026 Published: 03.02.2026 Updated: 06.02.2026

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 6.5

Product Status

Vendor Kubernetes
Product ingress-nginx
Versions Default: affected
  • affected from 0 to 1.13.7 (excl.)
  • affected from 0 to 1.14.2 (excl.)

Credits

  • Matan Shabtay finder

References

Problem Types

  • CWE-770 Allocation of Resources Without Limits or Throttling CWE

Impacts

  • CAPEC-130 Excessive Allocation