CVE-2026-71327
🟡 Monitoruj
Błąd w Traefik umożliwia nadpisywanie backendów przez kolidujące trasy w różnych przestrzeniach nazw.
CVSS
8.1
EPSS
0.4%
Exploit
none
Vendor
traefik
Opis źródłowy (NVD)
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
brak
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.4% |
| Opublikowano (NVD) | 2026-08-06 22:18:29 UTC |
| Ostatnia modyfikacja (NVD) | 2026-09-16 20:44:53 UTC |
Referencje
- https://github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9 ([email protected]) [Patch]
- https://github.com/traefik/traefik/pull/13580 ([email protected]) [Issue Tracking, Patch]
- https://github.com/traefik/traefik/releases/tag/v3.6.25 ([email protected]) [Patch, Release Notes]
- https://github.com/traefik/traefik/releases/tag/v3.7.10 ([email protected]) [Patch, Release Notes]
- https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx ([email protected]) [Patch, Vendor Advisory]