Ingress-nginx path sanitization can be bypassed with log_format directive.
path
log_format
{ "cpes": [ "cpe:2.3:a:kubernetes:ingress-nginx:*:*:*:*:*:*:*:*" ], "severity": "Medium" }
"https://github.com/bitnami/vulndb/tree/main/data/nginx-ingress-controller/BIT-nginx-ingress-controller-2022-4886.json"