cbcvebase.

F5 Nginx Ingress Controller vulnerabilities

24 known vulnerabilities affecting f5/nginx_ingress_controller.

Total CVEs
24
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
2
Severity breakdown
HIGH14MEDIUM10

Vulnerabilities

Page 2 of 2
CVE-2022-41742P4HIGHCVSS 7.1≥ 1.9.0, ≤ 1.12.4≥ 2.0.0, ≤ 2.4.02022-10-19
CVE-2022-41742 [HIGH] CWE-787 CVE-2022-41742: NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions NGINX Open Source before versions 1.23.2 and 1.22.1, NGINX Open Source Subscription before versions R2 P1 and R1 P1, and NGINX Plus before versions R27 P1 and R26 P1 have a vulnerability in the module ngx_http_mp4_module that might allow a local attacker to cause a worker process crash, or might result in worker process memory disclosure by using a spe
nvd
CVE-2026-48142P4MEDIUMCVSS 4.8≥ 3.5.0, ≤ 3.7.2≥ 4.0.0, ≤ 4.0.1+1 more2026-06-17
CVE-2026-48142 [MEDIUM] CWE-125 CVE-2026-48142: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When co NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their con
nvd
CVE-2026-40701P4MEDIUMCVSS 4.8≥ 3.5.0, ≤ 3.7.2≥ 4.0.0, ≤ 4.0.1+1 more2026-05-13
CVE-2026-40701 [MEDIUM] CWE-416 CVE-2026-40701: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssl_module module when the ssl_verify_client directive is set to "on" or "optional," and the ssl_ocsp directive is set to "on" or the leaf parameters are configured with a resolver. With this configuration, an unauthenticated attacker can send requests along with conditions beyond
nvd
CVE-2024-10318P4MEDIUMCVSS 5.4≤ 1.12.5≥ 2.2.1, ≤ 2.4.2+2 more2024-11-06
CVE-2024-10318 [MEDIUM] CWE-384 CVE-2024-10318: A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where A session fixation issue was discovered in the NGINX OpenID Connect reference implementation, where a nonce was not checked at login time. This flaw allows an attacker to fix a victim's session to an attacker-controlled account. As a result, although the attacker cannot log in as the victim, they can force the session to associate it with the attacke
nvd
F5 Nginx Ingress Controller vulnerabilities | cvebase