Record summary

CVE-2026-44774 has a selected CVSS score of 6.4 (medium).

Description

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider accepts any TraefikService backend reference whose name ends with @internal, making it possible to route traffic to rest@internal in addition to the intended api@internal. In shared Gateway deployments where the REST provider is enabled, this allows a low-privileged actor to gain live dynamic configuration write access to Traefik, enabling unauthorized reconfiguration of routers and services. This vulnerability is fixed in 2.11.46, 3.6.17, and 3.7.1.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated May 16, 2026 · Source: CVE List

Affected products and versions

7
ProductSourceVersion rangeStatus

Red Hat OpenShift Dev Spaces 3.29

Browse Red Hat / Red Hat OpenShift Dev Spaces 3.29devspaces/traefik-rhel9

Default status: affected

CVE List1782403274 to < *unaffected

Red Hat OpenShift GitOps

Browse Red Hat / Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8

Default status: unaffected

CVE ListVersion data not supplied

Red Hat OpenShift GitOps

Browse Red Hat / Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel9

Default status: unaffected

CVE ListVersion data not supplied
CVE List< 2.11.46affected
>= 3.0.0-beta1, < 3.6.17affected
>= 3.7.0-rc.0, < 3.7.1affected

github.com/traefik/traefik

Browse Go / github.com/traefik/traefik
GitHub AdvisoryThrough 1.7.34affected

github.com/traefik/traefik/v2

Browse Go / github.com/traefik/traefik/v2
GitHub AdvisoryBefore 2.11.46 · Fixed in 2.11.46affected

github.com/traefik/traefik/v3

Browse Go / github.com/traefik/traefik/v3
GitHub Advisory3.7.0affected
3.7.0 to < 3.7.1 · Fixed in 3.7.1affected
Before 3.6.17 · Fixed in 3.6.17affected

References

10