Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2pf9-vr92-6h3v

Опубликовано: 04 фев. 2026
Источник: github
Github: Прошло ревью
CVSS3: 6.5

Описание

ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

Пакеты

Наименование

k8s.io/ingress-nginx

go
Затронутые версииВерсия исправления

< 1.13.7

1.13.7

Наименование

k8s.io/ingress-nginx

go
Затронутые версииВерсия исправления

>= 1.14.0, < 1.14.3

1.14.3

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770

Связанные уязвимости

CVSS3: 6.5
nvd
4 дня назад

A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory.

EPSS

Процентиль: 12%
0.00039
Низкий

6.5 Medium

CVSS3

Дефекты

CWE-770