PT-2026-67289 · Traefik · Traefik

·

CVE-2026-67309

·

Published

2026-08-01

·

Updated

2026-09-04

CVSS v4.0

7.8

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions 3.7.0 through 3.7.7
Description A path traversal issue exists in the Kubernetes Ingress NGINX provider's RewriteTarget middleware, which is generated from the nginx.ingress.kubernetes.io/rewrite-target annotation. When an Ingress path utilizes a regex that captures attacker-controlled text without requiring a path separator, a crafted request can be rewritten to a dot-segment traversal path. Because the system forwards the request without post-replacement normalization validation, a backend that normalizes dot segments may resolve the path to a protected endpoint. This allows an attacker to bypass route-level authentication mechanisms such as BasicAuth, DigestAuth, or ForwardAuth.
Recommendations Update to version 3.7.8.

Exploit

Fix

Path traversal

Authentication Bypass Using an Alternate Path or Channel

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67309
GHSA-7QF5-7PPR-87V8
GHSA-8RXV-JG7P-WVG3
GO-2026-6207
OPENSUSE-SU-2026:21761-1

Affected Products

Traefik