Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54765

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 8.5

Описание

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.

A flaw was found in Traefik's Kubernetes Gateway API provider. An attacker capable of creating an accepted HTTPRoute that shares the same backend Service and port could exploit this vulnerability. The system may incorrectly apply the attacker's route filter context to another route's requests, potentially allowing unauthorized access or information disclosure across different namespaces. This could lead to the application of security-sensitive headers from the attacker's route to legitimate requests, bypassing intended security controls.

Отчет

This Moderate flaw in Traefik's Kubernetes Gateway API provider, as deployed in Red Hat OpenShift Dev Spaces, could allow an attacker to apply their route's filter context to other requests. This can lead to unauthorized access or information disclosure across namespace boundaries when backendRef filters are used for security-sensitive headers, as it allows bypassing intended security controls. Exploitation requires the attacker to create an accepted HTTPRoute.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-41
https://bugzilla.redhat.com/show_bug.cgi?id=2497555traefik: Traefik: Unauthorized filter context application in Kubernetes Gateway API provider

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.5
nvd
29 дней назад

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.

CVSS3: 8.5
debian
29 дней назад

Traefik is an open source HTTP reverse proxy and load balancer. From v ...

8.5 High

CVSS3