VDB

CVE-2026-54761

CVE-2026-54761 PUBLISHED CVSS 6 MEDIUM

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

EPSS 0.37% · 29.9th percentile

Risk Scores

CVSS 4.0
6
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
EPSS Score
0.37%
29.9th percentile

Affected Products

VendorProductVersions
traefiktraefik>= 3.7.0-ea.1, < 3.7.5, >= 3.7.0-ea.1, < 3.7.5, < 3.6.21
chainguardtraefik-2.110, 0, 0
chainguardtraefik-fips-2.110, 0, 0
alpinetraefik0, 0, 0
github.comtraefik/traefik0, 0, 0
github.comtraefik/traefik/v20, 0, 0
github.comtraefik/traefik/v30, 3.7.0-ea.1, 0

Timeline

  • Jun 11, 2026 CVE Published
  • Jun 19, 2026 Security Advisory
  • Aug 7, 2026 EPSS Score
  • Aug 24, 2026 EPSS Score
  • Aug 26, 2026 EPSS Score
  • Aug 30, 2026 EPSS Score
  • Sep 3, 2026 EPSS Score
  • Sep 6, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›