Authentication Bypass in Ingress-Nginx by NGINX, Inc.
CVE-2026-24513
What is CVE-2026-24513?
A vulnerability has been identified in the Ingress-Nginx controller that compromises its ability to enforce authentication properly. When configured with a specific custom-errors setting that erroneously handles HTTP error codes, it can allow unauthorized access to restricted resources. The issue arises when a default custom-errors backend is not functioning correctly, failing to adhere to the X-Code HTTP header specifications. Although the built-in custom-errors backend does not exhibit this problem, manually misconfigured setups can lead to significant security risks. This requires careful attention from administrators to prevent exploitation.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
ingress-nginx 0
ingress-nginx 0 < 1.13.7
ingress-nginx 0 < 1.14.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved