← Permission Reference
T1
create ingresses
Injected Ingress annotations into ingress-nginx enable SSRF and reading all cluster secrets via the ingress-nginx service account.
ingress-nginx (the controller project, not the core Ingress API) was retired by Kubernetes in March 2026, and no further security patches will ever be released, though it remains one of the most widely deployed ingress controllers.
✕ Won't FixCVE-2024-7646 ↗
Note:
CVE-2024-7646 is an ingress-nginx controller vulnerability, not core Kubernetes; annotation injection bypasses internal auth on the admission webhook.
ingress-nginx was retired in March 2026 (best-effort maintenance ended, no future CVE patches); migrate to Gateway API or another controller.
- API Group
- networking.k8s.io
- Scope
- namespaced
- Audit Level
- Request
