Ingress Nightmare: New Injection Threats in Kubernetes

Pentera Labs reveals three new critical injection points in the ingress-nginx controller,  building on Wiz’s IngressNightmare CVE.

These overlooked vulnerabilities could let attackers hijack traffic, spoof headers, or reach unauthorized backend services - They exist in one of the most widely used ingress controllers in Kubernetes, putting countless environments at risk.
This research highlights how small misconfigurations can lead to major exposure in modern cloud-native architectures.

What’s Inside:
  • 3 new injection vulnerabilities in ingress-nginx
  • How attackers find and exploit CVEs in open source
  • Actionable tips to secure your Kubernetes environment

Download Research >>>