Junglewise Threat Intelligence

CVE-2026-54761: Traefik authorization bypass in Kubernetes Gateway crossProviderNamespaces

CVE-2026-54761 · Severity: medium · CVSS 3.1 · Published 2026-06-23

Technologies: Traefik, Traefik Labs Traefik Proxy, github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Traefik, Traefik Labs, Go.

Executive brief

Traefik is a popular open-source tool used to manage and route web traffic into applications. A security flaw in its Kubernetes integration allows users in restricted areas of a network to bypass safety rules and access internal administrative interfaces, such as the Traefik dashboard or API. This could allow an unauthorized user to view sensitive configuration details or internal system information that should be protected.

Technical details

An authorization bypass exists in Traefik's Kubernetes Gateway provider due to incorrect validation of the 'crossProviderNamespaces' allowlist. When an HTTPRoute uses multiple backend references (Weighted Round Robin), Traefik checks the allowlist against the target 'backendRef.namespace' instead of the namespace where the route originated. An attacker with permissions to create an HTTPRoute in an untrusted namespace can reference internal TraefikServices (e.g., api@internal) by pointing the backend namespace to a trusted one, provided a Gateway API ReferenceGrant exists. This allows the exposure of internal Traefik services on the data plane. The issue is resolved in versions 3.6.21 and 3.7.5.

Affected products

  • Traefik Traefik < 3.6.21, >= 3.7.0-ea.1, < 3.7.5

Timeline

  • 2026-06-10: patched: Fixes included in releases 3.6.21 and 3.7.5
  • 2026-06-11: advisory: GitHub Security Advisory GHSA-3g6v-2r68-prfc published
  • 2026-06-23: disclosed: CVE-2026-54761 published to NVD

References

Related threats