PT-2026-63359 · Traefik · Traefik

·

CVE-2026-65601

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions 3.7.0 through 3.7.6
Description A namespace confusion issue exists in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, the system incorrectly uses the backend Service namespace instead of the HTTPRoute namespace. This allows a low-privileged route author with a ReferenceGrant for a cross-namespace Service to bind a Traefik Middleware from the backend namespace without the required separate grant, which could lead to the injection of trusted reverse-proxy identity headers into downstream requests.
Recommendations Update Traefik to version 3.7.7.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65601
GHSA-QQ9Q-X9W4-CHHJ

Affected Products

Traefik