Kubetier
← Permission Reference
T1

create ingresses

Injected Ingress annotations into ingress-nginx enable SSRF and reading all cluster secrets via the ingress-nginx service account.

ingress-nginx, the controller project rather than the core Ingress API, was retired by Kubernetes in March 2026.

No further security patches will be released, and it remains one of the most widely deployed ingress controllers.

✕ Won't FixCVE-2024-7646won't fix↗

Note:

CVE-2024-7646 is an ingress-nginx controller vulnerability, not core Kubernetes; annotation injection bypasses internal auth on the admission webhook.

ingress-nginx was retired in March 2026 (best-effort maintenance ended, no future CVE patches); migrate to Gateway API or another controller.

API Group
networking.k8s.io
Scope
namespaced
Audit Level
Request
K8s docs ↗