MEDIUM GitHub

CVE-2026-54765

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

## Summary There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider. When two accepted HTTPRoutes target the same backend Service:port but configure different `backendRef` filters, Traefik may resolve both routes to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where `backendRef` filters set security-sensitive headers — such as tenant identity, authorization context, or values the backend t

Affected Products

References

Published: 2026-08-06 · Source: GitHub · Feed updated: 2026-08-07
This medium severity vulnerability was published on 2026-08-06 via GitHub. Affected: go/github.com/traefik/traefik/v3 >= 3.7.0, <= 3.7.5.
vulnfeed aggregates 9207 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.