PT-2026-68799 · Traefik · Traefik

CVE-2026-71327

·

Published

2026-07-29

·

Updated

2026-09-04

CVSS v3.1

8.2

High

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 3.6.25 Traefik versions prior to 3.7.10
Description Traefik's Kubernetes Gateway API provider incorrectly constructs router and service identities for HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute objects by hyphen-concatenating the namespace, route name, Gateway identity, entry point, and rule index. Because Kubernetes names can contain hyphens, this construction is not injective, meaning two different routes can produce the same identity. An attacker with permission to create a route in a colliding namespace or name combination can cause their route to overwrite another namespace's backend. This allows the attacker to redirect traffic, including credentials and authorization headers, to a backend they control.
Recommendations Update Traefik to version 3.6.25. Update Traefik to version 3.7.10.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11280
CVE-2026-71327
GHSA-FGJJ-PX3W-67XX
GO-2026-6209
OPENSUSE-SU-2026:21761-1

Affected Products

Traefik