Back

MEDIUM

Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef

Published Jul 22, 2026

Description

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.

Affected products

Remediation

Red Hat statement

This is an Important flaw in Traefik's Kubernetes Gateway API provider, affecting Red Hat OpenShift Dev Spaces. A low-privileged user in a Kubernetes environment can exploit a namespace confusion vulnerability to bypass security controls. This allows for the incorrect binding of a Traefik Middleware from a different namespace, potentially leading to the injection of trusted identity headers and subsequent privilege escalation within the cluster.

Metrics

References (10)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Jul 22, 2026
Updated Jul 24, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Jul 23, 2026
NVD
Status Analyzed
Modified Aug 6, 2026
Red Hat
Severity Important
Public date Jul 22, 2026
GHSA-QQ9Q-X9W4-CHHJ