MEDIUM GitHub

CVE-2026-65601

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

## Summary There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute` namespace. A low-privileged route author holding a `ReferenceGrant` for a cross-namespace Service could therefore bind a Traefik `Middleware` from the backend namespace without a separate grant for that middleware. If the reused midd

Affected Products

References

Published: 2026-08-05 · Source: GitHub · Feed updated: 2026-08-06
This medium severity vulnerability was published on 2026-08-05 via GitHub. Affected: go/Traefik >= 3.7.0, < 3.7.7.
vulnfeed aggregates 9338 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.