What is CVE-2026-15228?
CVE-2026-15228 in Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The vulnerability arises because KIC collects CA-certificate Secrets using only a label selector, without verifying ingress-class or namespace restrictions. Users should upgrade to a patched version to mitigate this issue.
Azərbaycanca: CVE-2026-15228, Kong Kubernetes Ingress Controller (KIC) istifadəçiyə namespace səviyyəsində Secret yaratmaq icazəsi ilə bütün cluster miqyasında ingress konfiqurasiyasına denial-of-service hücumu etməyə imkan verir. Bu zəiflik, KIC-in CA-sertifikat Secret-lərini yalnız label ilə toplaması və ingress-class və ya namespace fərqləndirməməsi səbəbindən baş verir. Təsirə məruz qalmamaq üçün bu cür zəiflikləri aradan qaldırmış yeni versiyaya yüksəlmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-284
FAQ1
How is CVE-2026-15228 exploited in Kong Kubernetes Ingress Controller?
Even if a user only has namespace-scoped Secret creation privileges, because KIC collects CA-certificate Secrets using only a label selector, they can create these Secrets in a way that affects the cluster-wide ingress configuration, causing a denial of service.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.