CVE-2026-54765
published 2026-07-06CVE-2026-54765: Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted…
PriorityP350high8.5CVSS 3.1
AVNACLPRLUINSCCLIHAN
EPSS
0.28%
19.9th percentile
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | traefik-rhel9 | — | — |
| github.com | traefik_traefik_v3 | >= 3.7.0 < 3.7.6 | 3.7.6 |
| traefik | traefik | — | — |
| traefik | traefik | >= 3.7.0 < 3.7.6 | 3.7.6 |
CVSS provenance
nvdv3.18.5HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N
nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
ghsa·2026-08-06
CVE-2026-54765 [MEDIUM] CWE-284 Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
## Summary
There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route's filter set to all requests reaching that backend. In Gateway deployments
where `backendRef` filters set security-sensitive headers — such as tenant identity,
authorization context, or values the backend trusts — an attacker who can create an
accepted HTTPRoute sharing the same backend Service:port may cause their route's filter
context to be applied to another route's requests, potentially cr
VulDB
Traefik up to 3.7.5 Kubernetes Gateway API Provider improper authorization
vuldb·2026-07-06·CVSS 6.3
CVE-2026-54765 [MEDIUM] Traefik up to 3.7.5 Kubernetes Gateway API Provider improper authorization
A vulnerability categorized as problematic has been discovered in Traefik up to 3.7.5. This affects an unknown function of the component Kubernetes Gateway API Provider. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2026-54765. The attack may be performed from remote. There is no available exploit.
Red Hat
traefik: Traefik: Unauthorized filter context application in Kubernetes Gateway API provider
vendor_redhat·2026-07-06·CVSS 8.5
CVE-2026-54765 [HIGH] CWE-41 traefik: Traefik: Unauthorized filter context application in Kubernetes Gateway API provider
traefik: Traefik: Unauthorized filter context application in Kubernetes Gateway API provider
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing
No detection rules found.
No public exploits indexed.
2026-07-06
Published