A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/136680 |
|
History
Tue, 03 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory. | |
| Title | ingress-nginx Admission Controller denial of service | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-02-03T22:17:25.137Z
Reserved: 2026-01-23T06:54:35.913Z
Link: CVE-2026-24514
No data.
Status : Received
Published: 2026-02-03T23:16:07.280
Modified: 2026-02-03T23:16:07.280
Link: CVE-2026-24514
No data.
OpenCVE Enrichment
No data.
Weaknesses