Junglewise Threat Intelligence

CVE-2026-65601: Traefik namespace confusion in Kubernetes Gateway API extensionRef

CVE-2026-65601 · Severity: medium · CVSS 4 · Published 2026-07-22

Technologies: Traefik Labs Traefik Proxy, github.com/traefik/traefik (Go). Vendors: Traefik Labs, Go.

Executive brief

Traefik, a popular cloud-native application proxy and load balancer, contains a vulnerability in how it handles traffic rules in Kubernetes environments. An attacker with limited permissions to create network routes could trick the system into applying security settings (middlewares) from a different, more privileged area of the network. This could allow the attacker to bypass authentication or impersonate other users in downstream applications like Grafana or Jenkins by injecting unauthorized identity headers.

Technical details

A namespace-confusion vulnerability exists in Traefik's Kubernetes Gateway API provider when resolving 'HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef'. The root cause is that Traefik incorrectly reuses the backend Service's namespace instead of the HTTPRoute's namespace when resolving extension filters. A low-privileged attacker with 'ReferenceGrant' access to a cross-namespace Service can bind a Traefik 'Middleware' from that backend namespace without explicit authorization. If the bound middleware is configured to inject identity headers (e.g., X-WEBAUTH-USER), the attacker can achieve unauthorized authenticated state in downstream applications. This issue is fixed in version 3.7.7.

Affected products

  • Traefik Labs Traefik >= 3.7.0, < 3.7.7

Timeline

  • 2026-07-09: advisory: Initial GitHub Advisory published
  • 2026-08-05: patched: Fix released in version 3.7.7

References

Related threats