MEDIUM GitHub
CVE-2026-65601
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
## Summary
There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute` namespace. A low-privileged route author holding a `ReferenceGrant` for a cross-namespace Service could therefore bind a Traefik `Middleware` from the backend namespace without a separate grant for that middleware. If the reused midd
Affected Products
- go/Traefik >= 3.7.0, < 3.7.7
References
- https://github.com/advisories/GHSA-qq9q-x9w4-chhj
- https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj
- https://nvd.nist.gov/vuln/detail/CVE-2026-65601
- https://github.com/traefik/traefik/pull/13462
This medium severity vulnerability was published on 2026-08-05 via GitHub. Affected: go/Traefik >= 3.7.0, < 3.7.7.
vulnfeed aggregates 9338 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.