CVE-2026-65602
published 2026-07-22CVE-2026-65602: Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport…
PriorityP351high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.18%
8.2th percentile
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devspaces | traefik-rhel9 | — | — |
| github.com | traefik_traefik_v3 | >= 3.6.0 < 3.6.23 | 3.6.23 |
| github.com | traefik_traefik_v3 | >= 3.7.0 < 3.7.7 | 3.7.7 |
| traefik | traefik | >= 3.6.0 < 3.6.23 | 3.6.23 |
| traefik | traefik | >= 3.7.0 < 3.7.7 | 3.7.7 |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
ghsa·2026-08-05
CVE-2026-65602 [MEDIUM] CWE-863 Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
## Summary
There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privileged Kubernetes user in a namespace that is not listed in `crossProviderNamespaces` could set `serversTransport: foo@file` on an `IngressRouteTCP` service, causing Traefik to accept the forbidden cross-provider reference and use the file-provider `TCPServersTransport` — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. The fix applies the `crossProviderNamespaces` allo
GHSA
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for
ghsa_unreviewed·2026-07-22
CVE-2026-65602 [MEDIUM] CWE-863 Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
Red Hat
traefik: Traefik: Information disclosure and integrity bypass via IngressRouteTCP cross-provider reference
vendor_redhat·2026-07-22·CVSS 5.3
CVE-2026-65602 [MEDIUM] CWE-863 traefik: Traefik: Information disclosure and integrity bypass via IngressRouteTCP cross-provider reference
traefik: Traefik: Information disclosure and integrity bypass via IngressRouteTCP cross-provider reference
A flaw was found in Traefik. A low-privileged Kubernetes user can bypass the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references. By setting a forbidden cross-provider reference, Traefik may use a file-provider TCPServersTransport. This can lead to the exposure of privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings, resulting in information disclosure and potential integrity compromise.
Statement: Red Hat OpenShift Dev Spaces ships a version of traefik affected by this vulnerability. The flaw allows a low-privileged Kubernetes user to bypass the crossProviderNamespaces allowlist for IngressRouteTCP service se
No detection rules found.
No public exploits indexed.
2026-07-22
Published