Namespace Confusion Vulnerability in Traefik Kubernetes Gateway API
CVE-2026-65601
5.3MEDIUM
What is CVE-2026-65601?
Traefik versions 3.7.0 through 3.7.6 experienced a namespace confusion vulnerability within its Kubernetes Gateway API provider. This issue arose when resolving the backend references in HTTPRoute specifications, leading to low-privileged route authors being able to bind Traefik Middleware from a different namespace. Without the need for permission to grant access to this middleware, it posed a risk of injecting trusted reverse-proxy identity headers into downstream requests. The vulnerability was addressed and resolved in version 3.7.7.
Affected Version(s)
traefik 3.7.0 < 3.7.7
traefik 3.7.7
