Junglewise Threat Intelligence

Traefik IngressRouteTCP authorization bypass in serversTransport references

Severity: medium · CVSS 5.3 · Published 2026-07-22

Technologies: Traefik, github.com/traefik/traefik (Go). Vendors: Traefik, Go.

Executive brief

Traefik, a popular cloud-native application proxy, contains a security flaw in how it handles network traffic routing in Kubernetes environments. A user with limited permissions could bypass security restrictions to use unauthorized connection settings, such as high-privilege identity certificates or specialized network protocols. This could allow an attacker to impersonate legitimate services or gain unauthorized access to backend systems. The issue is resolved in versions 3.6.23 and 3.7.7.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in Traefik's Kubernetes CRD provider. While the 'crossProviderNamespaces' allowlist is correctly enforced for HTTP references, it is bypassed for IngressRouteTCP 'serversTransport' references. A low-privileged Kubernetes user in a restricted namespace can reference a file-provider 'TCPServersTransport' (e.g., 'foo@file'). This allows the attacker to utilize privileged backend mTLS client certificates, SPIFFE identities, or PROXY-protocol settings defined by the operator. The vulnerability is exploited by creating an IngressRouteTCP resource that points to a transport configuration the namespace is not authorized to use. The fix, implemented in versions 3.6.23 and 3.7.7, applies the allowlist validation to TCP transport references.

Affected products

  • traefik traefik 3.6.0 - 3.6.22, 3.7.0 - 3.7.6

Timeline

  • 2026-07-09: advisory: Original advisory GHSA-42cj-m3vj-89wv published
  • 2026-07-22: advisory: Duplicate advisory GHSA-7m3p-wc52-rmc6 published
  • 2026-08-05: other: Duplicate advisory GHSA-7m3p-wc52-rmc6 withdrawn

References

Related threats