Description
VMware ESXi, Workstation, and Fusion contain an information disclosure vulnerability due to an out-of-bounds read in HGFS. A malicious actor with administrative privileges to a virtual machine may be able to exploit this issue to leak memory from the vmx process.
Statistics
- 2 Posts
Last activity: 6 hours ago
Overview
Description
VMware ESXi, and Workstation contain a TOCTOU (Time-of-Check Time-of-Use) vulnerability that leads to an out-of-bounds write. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
Statistics
- 2 Posts
Last activity: 6 hours ago
Overview
- Kubernetes
- ingress-nginx
03 Feb 2026
Published
05 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.10%
KEV
Description
A security issue was discovered in ingress-nginx cthe `rules.http.paths.path` Ingress field can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Statistics
- 2 Posts
Last activity: 22 hours ago
Bluesky
🔴 CVE-2026-1580 and CVE-2026-24512 allow for config #injection via the "nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively.
🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests.
Overview
- Kubernetes
- ingress-nginx
03 Feb 2026
Published
05 Feb 2026
Updated
CVSS v3.1
HIGH (8.8)
EPSS
0.10%
KEV
Description
A security issue was discovered in ingress-nginx where the `nginx.ingress.kubernetes.io/auth-method` Ingress annotation can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default installation, the controller can access all Secrets cluster-wide.)
Statistics
- 2 Posts
Last activity: 22 hours ago
Bluesky
🔴 CVE-2026-1580 and CVE-2026-24512 allow for config #injection via the "nginx.ingress.kubernetes.io/auth-method" ingress annotation and the "rules.http.paths.path" ingress field, respectively.
🟡 CVE-2026-24514 is a #DoS in the ingress-nginx admission controller, triggered by sending large requests.