CVE-2026-65601
Reported by VulnCheck · Published July 22, 2026
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| traefik | traefik | 3.7.0, 3.7.7 |
| traefik | traefik | 3.7.0, 3.7.7, 3.7.0 |
Timeline
- Jul 9, 2026 CVE Published
- Jul 26, 2026 EPSS Score
- Jul 27, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
- Aug 24, 2026 EPSS Score
- Aug 28, 2026 EPSS Score
- Sep 4, 2026 EPSS Score
- Sep 9, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 16, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-qq9q-x9w4-chhj) vendor-advisory
- Patch Commit patch
- VulnCheck Advisory: Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef third-party-advisory