CVE 6.5 MEDIUM

ingress-nginx Admission Controller denial of service_CVE-2026-24514

6.5 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Description

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

Basic Information

ID CVE-2026-24514
Source kubernetes
Published Feb 3, 2026 at 22:17

Affected Product

Vendor Kubernetes
Product ingress-nginx
Affected Versions Kubernetes ingress-nginx 0
Kubernetes ingress-nginx 0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.