Description
When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate.



Impact:
The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only.

Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Published: 2026-07-15
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authenticated attacker with permissions to create or modify Ingress or TransportServer resources can submit a malformed resource to the NGINX Ingress Controller. The controller then terminates and enters a persistent crash loop, effectively denying availability of the control plane. The vulnerability does not affect the data plane or expose data, but the controller becomes unavailable until restarted or until the malformed resource is removed. The weakness is classified as CWE‑476, a null-pointer dereference type of defect.

Affected Systems

The affected product is the NGINX Ingress Controller supplied by F5. Specific affected versions are not listed in the available data; only supported, non-EoTS releases are considered.

Risk and Exploitability

The CVSS score of 7.1 indicates a high severity service. The EPSS score of less than 1% suggests exploitation is unlikely, and the vulnerability is not included in the CISA KEV catalog. The likely attack vector is a remote, authenticated API call to create or edit Ingress or must have sufficient RBAC permissions on the cluster to submit the harmful resource. Once triggered, the service crashes and requires a restart or removal of the resource to recover.

Generated by OpenCVE AI on July 31, 2026 at 03:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the NGINX Ingress Controller to a version where the null-pointer issue is fixed
  • Apply RBAC accounts can create or modify Ingress or TransportServer resources
  • If an immediate upgrade is not possible, manually delete any malformed Ingress or TransportServer resources and restart the controller to restore operation

Generated by OpenCVE AI on July 31, 2026 at 03:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared F5
F5 nginx Ingress Controller
Vendors & Products F5
F5 nginx Ingress Controller

Wed, 15 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Description When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Title NGINX Ingress Controller vulnerability
Weaknesses CWE-476
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

F5 Nginx Ingress Controller
cve-icon MITRE

Status: PUBLISHED

Assigner: f5

Published:

Updated: 2026-07-15T15:36:57.172Z

Reserved: 2026-06-17T23:45:50.281Z

Link: CVE-2026-52865

cve-icon Vulnrichment

Updated: 2026-07-15T15:36:53.176Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T03:45:04Z

Weaknesses