Skip to content
[Vulnerability Alert] Ingres-nginx Command Injection Vulnerability (CVE-2026-4342)

[Vulnerability Alert] Ingres-nginx Command Injection Vulnerability (CVE-2026-4342)

Docs.Byteplus • March 21, 2026

Ingress-nginx is the Ingress controller for Kubernetes, using nginx as a reverse proxy and load balancer. On March 20, 2026, the Kubernetes community disclosed a code injection vulnerability in Ingress Nginx, allowing attackers with Ingress creation privileges to inject malicious configurations, obtain the secret, and take over the cluster.

As of March 20, 2026, 10:00:00 (UTC+8).

ingress-nginx < 1.13.9

1.14.0 <= ingress-nginx < 1.14.5

1.15.0 <= ingress-nginx < 1.15.1

Upgrade ingress-nginx to version 1.13.9、1.14.5、1.15.1, or higher.

Ingress-Nginx will soon cease official maintenance. Updates and vulnerability fixes will stop after March 2026. Please pay attention to alternative solutions and migrate in time

[Product announcement] NGINX Ingress EOM

Ingress NGINX Retirement: What You Need to Know

Install admittance holdout groups (e.g. Kyverno, Gatekeeper) in the cluster to verify the creation of Ingress objects and block exploit vulnerabilities.

Convergence creates Ingress permissions that are only authorized to trusted users.

Extracted Entities