Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-2pf9-vr92-6h3v | ingress-nginx vulnerable to Allocation of Resources Without Limits or Throttling |
| Link | Providers |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/136680 |
|
Wed, 04 Feb 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubernetes
Kubernetes ingress-nginx |
|
| Vendors & Products |
Kubernetes
Kubernetes ingress-nginx |
Tue, 03 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in ingress-nginx where the validating admission controller feature is subject to a denial of service condition. By sending large requests to the validating admission controller, an attacker can cause memory consumption, which may result in the ingress-nginx controller pod being killed or the node running out of memory. | |
| Title | ingress-nginx Admission Controller denial of service | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-02-18T17:29:47.895Z
Reserved: 2026-01-23T06:54:35.913Z
Link: CVE-2026-24514
Updated: 2026-02-04T14:39:10.315Z
Status : Deferred
Published: 2026-02-03T23:16:07.280
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-24514
No data.
OpenCVE Enrichment
Updated: 2026-04-18T00:00:09Z
Github GHSA