PT-2026-63360 · Traefik · Traefik

·

CVE-2026-65602

·

Published

2026-07-22

·

Updated

2026-09-04

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Traefik versions 3.6.0 through 3.6.22 Traefik versions 3.7.0 through 3.7.6
Description Traefik fails to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references, as the allowlist was only applied to HTTP references. A low-privileged Kubernetes user in a namespace not included in the crossProviderNamespaces list can configure serversTransport: foo@file on an IngRouteTCP service. This allows Traefik to accept a forbidden cross-provider reference and utilize a file-provider TCPServersTransport, potentially granting access to privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings.
Recommendations Update Traefik versions 3.6.0 through 3.6.22 to version 3.6.23. Update Traefik versions 3.7.0 through 3.7.6 to version 3.7.7.

Exploit

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-65602
GHSA-42CJ-M3VJ-89WV
GHSA-7M3P-WC52-RMC6
GO-2026-6192
OPENSUSE-SU-2026:21761-1

Affected Products

Traefik