MEDIUM GitHub
CVE-2026-65602
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
## Summary
There is a medium-severity cross-provider reference vulnerability in Traefik's Kubernetes CRD provider. The `crossProviderNamespaces` allowlist is enforced for HTTP `serversTransport` references but was not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privileged Kubernetes user in a namespace that is not listed in `crossProviderNamespaces` could set `serversTransport: foo@file` on an `IngressRouteTCP` service, causing Traefik to accept the forbidden cro
Affected Products
- go/github.com/traefik/traefik/v3 >= 3.6.0, <= 3.6.22
- go/github.com/traefik/traefik/v3 >= 3.7.0, <= 3.7.6
References
- https://github.com/advisories/GHSA-42cj-m3vj-89wv
- https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv
- https://nvd.nist.gov/vuln/detail/CVE-2026-65602
- https://github.com/traefik/traefik/pull/13458
This medium severity vulnerability was published on 2026-08-05 via GitHub. Affected: go/github.com/traefik/traefik/v3 >= 3.6.0, <= 3.6.22, go/github.com/traefik/traefik/v3 >= 3.7.0, <= 3.7.6.
vulnfeed aggregates 9338 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.