SEPTEMBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-52865

MEDIUM · CVSS 6.5 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-15 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

The NGINX Ingress Controller is vulnerable to a denial-of-service (DoS) attack, where an authenticated remote attacker with permissions to modify Ingress or TransportServer resources can exploit this flaw to crash the control plane process, leading to persistent outages. This vulnerability primarily affects environments where such permissions are granted, making it critical for organizations using NGINX Ingress Controller to prioritize patching or implementing mitigations to prevent service disruptions.

CVE
CVE-2026-52865
Severity
MEDIUM
CVSS
6.5
EPSS
0.29%
Nginx

Original NVD Description

When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and enters a persistent crash loop while the malformed Ingress or TransportServer resource remains in the cluster. This vulnerability allows a remote, authenticated attacker with at least Ingress or TransportServer resource write access to cause a denial-of-service (DoS) on the NGINX Ingress Controller system. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Related CVEs

Other vulnerabilities affecting the same vendor(s)