Record summary

CVE-2026-29777 has a selected CVSS score of 6.1 (medium).

Description

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can bypass listener hostname constraints and redirect traffic for victim hostnames to attacker-controlled backends. This vulnerability is fixed in 3.6.10.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 11, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus
CVE List< 3.6.10affected

github.com/traefik/traefik

Browse Go / github.com/traefik/traefik
GitHub AdvisoryThrough 1.7.34affected

github.com/traefik/traefik/v2

Browse Go / github.com/traefik/traefik/v2
GitHub AdvisoryThrough 2.11.40affected

github.com/traefik/traefik/v3

Browse Go / github.com/traefik/traefik/v3
GitHub AdvisoryBefore 3.6.10 · Fixed in 3.6.10affected

References

4