ingress-nginx has Improper Check for Unusual or Exceptional Conditions
Low severity
GitHub Reviewed
Published
Feb 4, 2026
to the GitHub Advisory Database
•
Updated Feb 4, 2026
Package
Affected versions
< 1.13.7
>= 1.14.0, < 1.14.3
Patched versions
1.13.7
1.14.3
Description
Published by the National Vulnerability Database
Feb 3, 2026
Published to the GitHub Advisory Database
Feb 4, 2026
Reviewed
Feb 4, 2026
Last updated
Feb 4, 2026
A security issue was discovered in ingress-nginx where the protection afforded by the
auth-urlIngress annotation may not be effective in the presence of a specific misconfiguration.If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the
auth-urlannotation may be accessed even when authentication fails.Note that the built-in custom-errors backend works correctly. Triggering this issue requires an administrator to specifically configure ingress-nginx with a broken external component.
References