Executive brief
A vulnerability in Traefik's Kubernetes Gateway API provider can cause security settings to be incorrectly shared between different web routes. If two routes point to the same backend service but use different security rules (like adding identity headers), Traefik may accidentally apply one route's rules to the other. This could allow an attacker to bypass security controls or impersonate other users by leaking sensitive context across different parts of the network.
Technical details
The vulnerability exists in Traefik's Kubernetes Gateway API provider within `pkg/provider/kubernetes/gateway/httproute.go`. When generating dynamic HTTP backend service keys for `HTTPRoute` `backendRef`, Traefik uses only the namespace, Service name, protocol, and port, omitting the route or filter identity. If two routes target the same backend Service:port with different `backendRef` filters, the generated keys collide, and one configuration overwrites the other during the `maps.Copy` merge process. An attacker with permission to create an `HTTPRoute` can exploit this to force their filter context (e.g., headers used for auth or multi-tenancy) onto a victim's route. This is particularly impactful in cross-namespace deployments where `ReferenceGrant` is used.
Affected products
- traefik traefik >= 3.7.0, <= 3.7.5
Timeline
- 2026-06-04: disclosed: Discovered and reproduced by researchers.
- 2026-07-01: advisory: Initial GitHub Advisory published.
- 2026-08-06: patched: Version 3.7.6 released.