Back Docs.Byteplus [Vulnerability Alert] Ingres-nginx Command Injection Vulnerability (CVE-2026-4342)
Ingress-nginx is the Ingress controller for Kubernetes, using nginx as a reverse proxy and load balancer. On March 20, 2026, the Kubernetes community disclosed a code injection vulnerability in Ingress Nginx, allowing attackers with Ingress creation privileges to inject malicious configurations, obtain the secret, and take over the cluster.
As of March 20, 2026, 10:00:00 (UTC+8).
ingress-nginx < 1.13.9
1.14.0 <= ingress-nginx < 1.14.5
1.15.0 <= ingress-nginx < 1.15.1
Upgrade ingress-nginx to version 1.13.9、1.14.5、1.15.1, or higher.
Ingress-Nginx will soon cease official maintenance. Updates and vulnerability fixes will stop after March 2026. Please pay attention to alternative solutions and migrate in time
[Product announcement] NGINX Ingress EOM
Ingress NGINX Retirement: What You Need to Know
Install admittance holdout groups (e.g. Kyverno, Gatekeeper) in the cluster to verify the creation of Ingress objects and block exploit vulnerabilities.
Convergence creates Ingress permissions that are only authorized to trusted users.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
