Saturday, 7 Feb 2026
Subscribe
logo
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Font ResizerAa
Data Center NewsData Center News
Search
  • Global
  • AI
  • Cloud Computing
  • Edge Computing
  • Security
  • Investment
  • Sustainability
  • More
    • Colocation
    • Quantum Computing
    • Regulation & Policy
    • Infrastructure
    • Power & Cooling
    • Design
    • Innovations
    • Blog
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
Data Center News > Blog > Global Market > Four new vulnerabilities found in Ingress NGINX
Global Market

Four new vulnerabilities found in Ingress NGINX

Last updated: February 6, 2026 7:57 am
Published February 6, 2026
Share
container orchestration, clusters, clustering, Kubernetes
SHARE

NGINX is a reverse proxy/load balancer that typically acts because the front-end internet visitors receiver and directs it to the applying service for information transformation. Ingress NGINX is a model utilized in Kubernetes because the controller for visitors coming into the infrastructure. It takes care of mapping visitors to pods of containers working jobs with out exposing the pods themselves.  Meghu says Ingress NGINX is the first visitors entry level, and is efficient as a result of its means to reload its configuration on the fly, permitting it to regulate to modifications inside a Kubernetes cluster.

These vulnerabilities solely have an effect on Ingress NGINX variations 1.13.7 and beneath, and 1.14.3 and beneath, if they’re put in on a Kubernetes cluster.

The warning comes simply weeks earlier than, as introduced at KubeCon in November, support for Ingress NGINX ends. Beginning in March, the undertaking will not obtain energetic upkeep, safety patches, or bug fixes.

Consultants have been urging Kubernetes directors to shift to a brand new controller ever since. They advocate Kubernetes Gateway API as the usual for visitors administration. Meghu notes it’s vendor impartial and broadly used. Different choices are controllers akin to Cilium Ingress, Traefik, or HAProxy Ingress.

Along with CVE-2026-24512, the opposite new vulnerabilities are CVE-2026-24513, thought-about by Meghu a low threat since an attacker must have a config containing particular errors to use, and CVE-2026-24514, which Meghu considers a medium threat. The controller may very well be topic to a denial of service if an attacker overwhelms it with requests.

These are simply the newest points with Ingress NGINX. Simply over a 12 months in the past, researchers at Wiz found a gaggle of holes dubbed IngressNightmare. They can enable unauthenticated customers to inject malicious NGINX configurations and execute malicious code into the Ingress NGINX pod, doubtlessly exposing all cluster secrets and techniques and resulting in cluster takeover.

See also  OpenHands Raises $18.8M to Scale Enterprise Cloud Coding Agents

Source link

TAGGED: Ingress, Nginx, vulnerabilities
Share This Article
Twitter Email Copy Link Print
Previous Article Forfusion partners with Stellium to support AI Growth Zone Forfusion partners with Stellium to support AI Growth Zone
Next Article DiDAX: Innovating DNA-based data applications DiDAX: Innovating DNA-based data applications
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Your Trusted Source for Accurate and Timely Updates!

Our commitment to accuracy, impartiality, and delivering breaking news as it happens has earned us the trust of a vast audience. Stay ahead with real-time updates on the latest events, trends.
FacebookLike
TwitterFollow
InstagramFollow
YoutubeSubscribe
LinkedInFollow
MediumFollow
- Advertisement -
Ad image

Popular Posts

€24m EU project to boost semiconductor chips innovation

The European Union (EU) is taking daring strides to reinforce its semiconductor chips sector by…

January 20, 2025

OV Loop Acquires Skipti

OV Loop, a Boston, UK-based firm constructing an app commerce community, acquired Skipti, a transportation…

July 22, 2024

Data Center Infrastructure Market Survey Report 2024 Along with Statistics, Forecasts till 2030

The report is designed to offer a holistic view of the Knowledge Heart Infrastructure Market…

March 26, 2024

OpenSSH vulnerability regreSSHion puts millions of servers at risk

“From a theoretical viewpoint, we should discover a helpful code path that, if interrupted on…

July 2, 2024

CultureAI Raises $10M in Series A Funding

CultureAI, a London, UK-based supplier of a human threat administration platform, raised $10M in Sequence…

July 21, 2024

You Might Also Like

A person watching a stream of videos on a tablet
Global Market

Ruckus makes some noise with preconfigured switches for AV-over-IP networks

By saad
SpaceX
Global Market

Musk’s million data centers in space won’t fly, say experts

By saad
Is your Java estate audit-ready – or just hoping for the best?
Global Market

Is your Java estate audit-ready – or just hoping for the best?

By saad
View on cooling towers of nuclear power plant thermal power station in which heat source is nuclear reactor, France, Europe, cheap energy source
Global Market

What hyperscalers’ hyper-spending on data centers tells us

By saad
Data Center News
Facebook Twitter Youtube Instagram Linkedin

About US

Data Center News: Stay informed on the pulse of data centers. Latest updates, tech trends, and industry insights—all in one place. Elevate your data infrastructure knowledge.

Top Categories
  • Global Market
  • Infrastructure
  • Innovations
  • Investments
Usefull Links
  • Home
  • Contact
  • Privacy Policy
  • Terms & Conditions

© 2024 – datacenternews.tech – All rights reserved

Welcome Back!

Sign in to your account

Lost your password?
We use cookies to ensure that we give you the best experience on our website. If you continue to use this site we will assume that you are happy with it.
You can revoke your consent any time using the Revoke consent button.