Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-qq9q-x9w4-chhj | Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion |
Sat, 25 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-348 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 23 Jul 2026 14:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 22 Jul 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7. | |
| Title | Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef | |
| First Time appeared |
Traefik
Traefik traefik |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Traefik
Traefik traefik |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-07-24T21:35:16.899Z
Reserved: 2026-07-22T10:48:36.000Z
Link: CVE-2026-65601
Updated: 2026-07-23T13:51:13.075Z
Status : Analyzed
Published: 2026-07-22T12:18:20.430
Modified: 2026-08-06T15:36:09.777
Link: CVE-2026-65601
OpenCVE Enrichment
Updated: 2026-08-04T00:00:09Z
Github GHSA