Threats Tagged 'cwe-76'
View all threats tagged with 'cwe-76'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-76'
Click on any threat for detailed analysis and mitigation recommendations
0 When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to create or modify these annotations may craft values that inject arbitrary NGINX configuration directives. Impact: An authenticated attacker granted write access to NGINX Ingress Controller Ingress annotations through the Kubernetes API may be able to inject arbitrary NGINX configuration directives, create or delete files, or disable services. There is no data plane exposure; this is a control plane issue only. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. Join the discussion | CVE Database V5 | 09/02/2026, 15:40:54 UTC Added: 09/02/2026, 15:53:04 UTC |
0 Description: When NGINX Plus is configured as the data plane for NGINX Gateway Fabric, an injection vulnerability exists in the NGINX configuration generator component of NGINX Gateway Fabric. User-supplied string values from the Authentication Filter Custom Resource Definition clientID or cookieName fields, or in the clientSecret field of a Secret referenced by an Authentication Filter, are rendered directly into NGINX configuration templates without sanitization or escaping. Impact: An authenticated attacker with permission to create or modify these resources may craft values that inject arbitrary NGINX configuration directives. This is a control plane issue; there is no data plane exposure. Join the discussion | CVE Database V5 | 09/02/2026, 15:40:54 UTC Added: 09/02/2026, 15:53:04 UTC |
0 CVE-2026-54722 is a high-severity vulnerability in the dssrf-js Node.js library prior to version 1.0.4. The issue involves improper neutralization of special elements in URL processing, specifically the '@' userinfo delimiter. This flaw allows an attacker to bypass internal IP validation checks, potentially causing a client to access internal services via crafted URLs. The vulnerability is fixed in version 1.0.4. Join the discussion | CVE Database V5 | 07/30/2026, 16:27:13 UTC Added: 07/30/2026, 16:52:57 UTC |
0 CVE-2026-55723 is an injection vulnerability in the configuration generator of F5 NGINX Ingress Controller when configured with Custom Resource Definitions (CRDs) or Ingress annotations. Authenticated users with permission to create or modify these CRDs or annotations can inject arbitrary NGINX configuration directives due to lack of sanitization of user-controllable fields. This vulnerability affects control plane operations only and does not expose the data plane. Versions 5.0.0 and 2026-lts-r1 are affected. Join the discussion | CVE Database V5 | 07/15/2026, 14:33:44 UTC Added: 07/15/2026, 14:48:46 UTC |
0 CVE-2026-11311 is an injection vulnerability in the NGINX configuration generator component of F5's NGINX Gateway Fabric version 2.5.0. Authenticated users with permission to create or modify certain Custom Resource Definitions can inject arbitrary NGINX configuration directives via unsanitized fields. There is no direct data plane exposure from this vulnerability. No official patch or remediation guidance is currently provided. Join the discussion | CVE Database V5 | 06/17/2026, 14:04:33 UTC Added: 06/17/2026, 15:07:07 UTC |
Showing 1 to 5 of 5 results