A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration.
If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails.
Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/kubernetes/kubernetes/issues/136679 |
|
History
Tue, 03 Feb 2026 22:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue was discovered in ingress-nginx where the protection afforded by the `auth-url` Ingress annotation may not be effective in the presence of a specific misconfiguration. If the ingress-nginx controller is configured with a default custom-errors configuration that includes HTTP errors 401 or 403, and if the configured default custom-errors backend is defective and fails to respect the X-Code HTTP header, then an Ingress with the `auth-url` annotation may be accessed even when authentication fails. Note that the built-in custom-errors backend works correctly. To trigger this issue requires an administrator to specifically configure ingress-nginx with a broken external component. | |
| Title | ingress-nginx auth-url protection bypass | |
| Weaknesses | CWE-754 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: kubernetes
Published:
Updated: 2026-02-03T22:17:17.315Z
Reserved: 2026-01-23T06:54:35.913Z
Link: CVE-2026-24513
No data.
Status : Received
Published: 2026-02-03T23:16:07.130
Modified: 2026-02-03T23:16:07.130
Link: CVE-2026-24513
No data.
OpenCVE Enrichment
No data.