Namespace Bypass in Traefik TCP ServersTransport Configuration
CVE-2026-65602
5.3MEDIUM
What is CVE-2026-65602?
The Traefik reverse proxy has a vulnerability affecting versions 3.6.0 to 3.6.22 and 3.7.0 to 3.7.6, where improper enforcement of the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references allows a low-privileged Kubernetes user to access unauthorized resources. This may expose sensitive configurations, including mTLS client certificates and SPIFFE identities, potentially compromising the integrity and confidentiality of backend services. Mitigation is available in newer versions 3.6.23 and 3.7.7.
Affected Version(s)
traefik 3.6.0 < 3.6.23
traefik 3.7.0 < 3.7.7
traefik 3.6.23
