A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration.
If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails.
Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/136679 |
|
History
Wed, 04 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubernetes
Kubernetes ingress-nginx |
|
| Vendors & Products |
Kubernetes
Kubernetes ingress-nginx |
Tue, 03 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails. Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component. | |
| Title | ingress-nginx auth-url protection bypass | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: kubernetes
Published: 2026-02-03T22:17:17.315Z
Updated: 2026-02-04T18:21:14.824Z
Reserved: 2026-01-23T06:54:35.913Z
Link: CVE-2026-24513
Updated: 2026-02-04T18:20:54.231Z
Status : Awaiting Analysis
Published: 2026-02-03T23:16:07.130
Modified: 2026-02-04T16:33:44.537
Link: CVE-2026-24513
No data.
ReportizFlow