If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails.
Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-4g2f-xcph-2335 | ingress-nginx has Improper Check for Unusual or Exceptional Conditions |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
| Link | Providers |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/136679 |
|
Wed, 04 Feb 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 04 Feb 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Kubernetes
Kubernetes ingress-nginx |
|
| Vendors & Products |
Kubernetes
Kubernetes ingress-nginx |
Tue, 03 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails. Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component. | |
| Title | ingress-nginx auth-url protection bypass | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-02-06T03:14:53.353Z
Reserved: 2026-01-23T06:54:35.913Z
Link: CVE-2026-24513
Updated: 2026-02-04T18:20:54.231Z
Status : Awaiting Analysis
Published: 2026-02-03T23:16:07.130
Modified: 2026-02-04T16:33:44.537
Link: CVE-2026-24513
No data.
OpenCVE Enrichment
Updated: 2026-02-04T12:05:46Z
Github GHSA