Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef
Published Jul 22, 2026
5.3
MEDIUMCVSS 4.0
EPSS 0.51%
Description
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
Affected products
-
- Version 3.7.0StatusaffectedConstraints<3.7.7
- Version 3.7.7StatusunaffectedConstraints-
- Version
No data.
Red Hat OpenShift Dev Spaces 3.30
devspaces/traefik-rhel9:1787756799
Fixed · RHSA-2026:62260
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Dev Spaces 3.30 | devspaces/traefik-rhel9:1787756799 | Fixed | RHSA-2026:62260 |
Traefik
Go
Introduced 3.7.0 Fixed 3.7.7github.com/traefik/traefik
Go
Introduced 0 Fixed not fixed
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | Traefik | 3.7.0 | 3.7.7 |
| Go | github.com/traefik/traefik | 0 | not fixed |
Remediation
Red Hat statement
This is an Important flaw in Traefik's Kubernetes Gateway API provider, affecting Red Hat OpenShift Dev Spaces. A low-privileged user in a Kubernetes environment can exploit a namespace confusion vulnerability to bypass security controls. This allows for the incorrect binding of a Traefik Middleware from a different namespace, potentially leading to the injection of trusted identity headers and subsequent privilege escalation within the cluster.
Metrics
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
1 other source (NVD) ▾
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
1 other source (Red Hat) ▾
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Jul 23, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 4, 2026.
Score over time
Jul-Oct 2026- EPSS v5
Percentile over time
- EPSS v5
Table of values (2 key points)
Flat stretches are collapsed. Showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 4, 2026 | 0.51% (0.00512) | 41.57th | v5 (v2026.06.15) |
| Jul 23, 2026 | 0.41% (0.00414) | 33.82th | v5 (v2026.06.15) |
References (10)
- https://access.redhat.com/security/cve/CVE-2026-65601 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2506094 Issue Tracking
- https://github.com/advisories/GHSA-qq9q-x9w4-chhj Advisory
- https://github.com/traefik/traefik/commit/26c96a3935cafb473f4a5bae1886560d9aa4e4f0 patch
- https://github.com/traefik/traefik/commit/655d6324ab4a1475892a958d4bae389720a67ea9
- https://github.com/traefik/traefik/pull/13462
- https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj vendor-advisoryVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-65601
- https://www.cve.org/CVERecord?id=CVE-2026-65601
- https://www.vulncheck.com/advisories/traefik-before-namespace-confusion-via-httproute-extensionref third-party-advisoryThird Party Advisory
Change history (0)
No recorded changes yet.