Impact
An authenticated attacker with permissions to create or modify Ingress or TransportServer resources can submit a malformed resource to the NGINX Ingress Controller. The controller then terminates and enters a persistent crash loop, effectively denying availability of the control plane. The vulnerability does not affect the data plane or expose data, but the controller becomes unavailable until restarted or until the malformed resource is removed. The weakness is classified as CWE‑476, a null-pointer dereference type of defect.
Affected Systems
The affected product is the NGINX Ingress Controller supplied by F5. Specific affected versions are not listed in the available data; only supported, non-EoTS releases are considered.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity service. The EPSS score of less than 1% suggests exploitation is unlikely, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is a remote, authenticated API call to create or edit Ingress or must have sufficient RBAC permissions on the cluster to submit the harmful resource. Once triggered, the service crashes and requires a restart or removal of the resource to recover.
OpenCVE Enrichment