Namespace Bypass in Traefik TCP ServersTransport Configuration
CVE-2026-65602

5.3MEDIUM

Key Information:

Vendor

Traefik

Status
Vendor
CVE Published:
22 July 2026

What is CVE-2026-65602?

The Traefik reverse proxy has a vulnerability affecting versions 3.6.0 to 3.6.22 and 3.7.0 to 3.7.6, where improper enforcement of the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references allows a low-privileged Kubernetes user to access unauthorized resources. This may expose sensitive configurations, including mTLS client certificates and SPIFFE identities, potentially compromising the integrity and confidentiality of backend services. Mitigation is available in newer versions 3.6.23 and 3.7.7.

Affected Version(s)

traefik 3.6.0 < 3.6.23

traefik 3.7.0 < 3.7.7

traefik 3.6.23

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

CuB3y0nd
james-yusuke
.