PT-2026-67289 · Traefik · Traefik

·

CVE-2026-67309

·

Published

2026-08-01

·

Updated

2026-08-01

CVSS v4.0

7.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions 3.7.0 through 3.7.7
Description A path traversal issue exists in the Kubernetes Ingress NGINX provider's RewriteTarget middleware, which is generated from the nginx.ingress.kubernetes.io/rewrite-target annotation. When an Ingress path utilizes a regex that captures attacker-controlled text without requiring a path separator, a crafted request can be rewritten to a dot-segment traversal path. Because the system forwards the request without post-replacement normalization validation, a backend that normalizes dot segments may resolve the path to a protected endpoint. This allows an attacker to bypass route-level authentication mechanisms such as BasicAuth, DigestAuth, or ForwardAuth.
Recommendations Update to version 3.7.8.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67309
GHSA-8RXV-JG7P-WVG3

Affected Products

Traefik