CVE-2022-4886: Kubernetes Ingress-Nginx

Medium severity, CVSS 6.5. EPSS: 1.6% chance of exploitation in the next 30 days.

Ingress-nginx `path` sanitization can be bypassed with `log_format` directive.

Affected products

  • Kubernetes Ingress-Nginx: before 1.8.0 (fixed in 1.8.0)

Published 2023-10-25. Last modified 2026-06-17.