Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.3
CVE-2026-55723EXPLOITEDPATCHED
f5 · nginx ingress controller

NGINX Ingress Controller vulnerability

Description

When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these CRDs or annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller CRDs or Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

Affected Products

VendorProductVersions
f5nginx ingress controller5.0.0, 2026-lts-r1

References

  • https://my.f5.com/manage/s/article/K000161800(vendor-advisory, patch)

Related News (1 articles)

Tier C
VulDB39d ago
CVE-2026-55723 | F5 NGINX Ingress Controller up to 5.5.1 Configuration Generator injection
→ No new info (linked only)
CVSS 3.18.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
5.5.22026-lts-r3
CWECWE-76
PublishedJul 15, 2026
Last enriched39d agov2
Tags
CVE-2026-55723
Trending Score0
Source articles1
Independent1
Info Completeness9/14
Missing: epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

PRE-CVE
Multiple Vulnerabilities in F5 Products
MEDIUMCVE-2026-60062EXP
NGINX Agent Vulnerability
HIGHCVE-2026-42530EXP
NGINX Open-Source ngx_http_v3_module vulnerability
HIGHCVE-2026-42055
NGINX ngx_http_proxy_v2_module and ngx_http_grpc_module vulnerability
HIGHCVE-2026-50107EXP
NGINX Gateway Fabric vulnerability

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Jul 15, 2026
Discovered by ZDM
Jul 15, 2026
Updated: severity, affectedVersions, activelyExploited, tags
Jul 15, 2026
Actively Exploited
Jul 16, 2026
Patch Available
Jul 16, 2026

Version History

v2
Last enriched 39d ago
v2Tier C39d ago

Updated severity to CRITICAL, added affected version 5.5.1, marked as actively exploited, and included new CVE tag.

severityaffectedVersionsactivelyExploitedtags
via VulDB
v139d ago

Initial creation