—
GO-2026-4796
ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
Quick fix
GO-2026-4796 — k8s.io/ingress-nginx: upgrade to the fixed version with the command below.
go get k8s.io/ingress-nginx@v0.0.0-20260319175635-5183b7d86137Details
ingress-nginx comment-based nginx configuration injection in k8s.io/ingress-nginx
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/k8s.io/ingress-nginx
Introduced in:
0Fixed in: 0.0.0-20260319175635-5183b7d86137Fix
go get k8s.io/ingress-nginx@v0.0.0-20260319175635-5183b7d86137References
- https://github.com/advisories/GHSA-f53h-mxv9-cp98[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-4342[ADVISORY]
- http://www.openwall.com/lists/oss-security/2026/03/19/9[WEB]
- https://github.com/kubernetes/ingress-nginx/commit/5183b7d861377a9a2f6d2acaf44f8f6abd5cd0aa[WEB]
- https://github.com/kubernetes/kubernetes/issues/137893[WEB]