PT-2026-67289 · Traefik · Traefik
CVSS v4.0
7.8
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions 3.7.0 through 3.7.7
Description
A path traversal issue exists in the Kubernetes Ingress NGINX provider's RewriteTarget middleware, which is generated from the
nginx.ingress.kubernetes.io/rewrite-target annotation. When an Ingress path utilizes a regex that captures attacker-controlled text without requiring a path separator, a crafted request can be rewritten to a dot-segment traversal path. Because the system forwards the request without post-replacement normalization validation, a backend that normalizes dot segments may resolve the path to a protected endpoint. This allows an attacker to bypass route-level authentication mechanisms such as BasicAuth, DigestAuth, or ForwardAuth.Recommendations
Update to version 3.7.8.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traefik