Known Vulnerabilities for Nginx Controller by F5
Listed below are 10 of the newest known vulnerabilities associated with "Nginx Controller" by "F5".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-55723 json | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vuln... | Not Provided | 2026-07-15 | 2026-07-16 |
| CVE-2026-52865 json | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permissi... | Not Provided | 2026-07-15 | 2026-07-15 |
| CVE-2026-43926 json | FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the password reset confirmat... | Not Provided | 2026-06-04 | 2026-06-04 |
| CVE-2026-3288 json | A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/rewrite-target` Ingress annotation ca... | Not Provided | 2026-03-09 | 2026-04-30 |
| CVE-2021-23021 json | The Nginx Controller 3.x before 3.7.0 agent configuration file /etc/controller-agent/agent.conf is world readable with curren... | 5.5 - MEDIUM | 2021-06-01 | 2021-06-11 |
| CVE-2021-23020 json | The NAAS 3.x before 3.10.0 API keys were generated using an insecure pseudo-random string and hashing algorithm which could l... | 5.5 - MEDIUM | 2021-06-01 | 2021-06-11 |
| CVE-2021-23019 json | The NGINX Controller 2.0.0 thru 2.9.0 and 3.x before 3.15.0 Administrator password may be exposed in the systemd.txt file tha... | 7.8 - HIGH | 2021-06-01 | 2022-08-30 |
| CVE-2021-23018 json | Intra-cluster communication does not use TLS. The services within the NGINX Controller 3.x before 3.4.0 namespace are using c... | 7.4 - HIGH | 2021-06-01 | 2021-06-11 |
| CVE-2020-27730 json | In versions 3.0.0-3.9.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller Agent does not use absolute paths when calling system u... | 9.8 - CRITICAL | 2020-12-11 | 2022-08-06 |
| CVE-2020-5911 json | In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages fr... | 7.3 - HIGH | 2020-07-02 | 2020-07-08 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | F5 | Nginx Controller | 3.9.0 | |||
| Application | F5 | Nginx Controller | 3.8.0 | |||
| Application | F5 | Nginx Controller | 3.7.0 | |||
| Application | F5 | Nginx Controller | 3.6.0 | |||
| Application | F5 | Nginx Controller | 3.5.0 | |||
| Application | F5 | Nginx Controller | 3.4.0 | |||
| Application | F5 | Nginx Controller | 3.3.0 | |||
| Application | F5 | Nginx Controller | 3.2.0 | |||
| Application | F5 | Nginx Controller | 3.12.0 | |||
| Application | F5 | Nginx Controller | 3.11.0 | |||
| Application | F5 | Nginx Controller | 3.10.0 | |||
| Application | F5 | Nginx Controller | 3.1.0 | |||
| Application | F5 | Nginx Controller | 3.0.0 | |||
| Application | F5 | Nginx Controller | 2.9.0 | |||
| Application | F5 | Nginx Controller | 2.8.1 | |||
| Application | F5 | Nginx Controller | 2.8.0 | |||
| Application | F5 | Nginx Controller | 2.7.0 | |||
| Application | F5 | Nginx Controller | 2.6.0 | |||
| Application | F5 | Nginx Controller | 2.5.0 | |||
| Application | F5 | Nginx Controller | 2.4.0 |