CVE-2026-54761

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik evaluates the allowlist against the target backendRef.namespace instead of the route's own namespace. As a result, an HTTPRoute created in a namespace that is not allow-listed can reference a cross-provider TraefikService such as api@internal, dashboard@internal or rest@internal by pointing backendRef.namespace at an allow-listed namespace covered by a Gateway API ReferenceGrant, exposing internal Traefik services on the data plane. Exploitation requires the ability to create an accepted HTTPRoute and a matching ReferenceGrant from an allow-listed namespace; it does not require any change to Traefik static configuration, RBAC, or the deployment itself. This vulnerability is fixed in 3.6.21 and 3.7.5.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*

History

26 Jun 2026, 16:37

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.1
CPE cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
References () https://github.com/traefik/traefik/releases/tag/v3.6.21 - () https://github.com/traefik/traefik/releases/tag/v3.6.21 - Release Notes, Patch
References () https://github.com/traefik/traefik/releases/tag/v3.7.5 - () https://github.com/traefik/traefik/releases/tag/v3.7.5 - Release Notes, Patch
References () https://github.com/traefik/traefik/security/advisories/GHSA-3g6v-2r68-prfc - () https://github.com/traefik/traefik/security/advisories/GHSA-3g6v-2r68-prfc - Exploit, Mitigation, Patch, Vendor Advisory
First Time Traefik
Traefik traefik

23 Jun 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 20:16

Updated : 2026-06-26 16:37


NVD link : CVE-2026-54761

Mitre link : CVE-2026-54761

CVE.ORG link : CVE-2026-54761


JSON object : View

Products Affected

traefik

  • traefik
CWE
CWE-284

Improper Access Control

CWE-863

Incorrect Authorization