CVE-2026-65602

MEDIUM

Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass

Title source: cna
STIX 2.1

Description

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.

References (3)

Core 3
Core References
Vendor Advisory vendor-advisory
GitHub Security Advisory (GHSA-42cj-m3vj-89wv)
https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv
Third Party Advisory third-party-advisory
VulnCheck Advisory: Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass
https://www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypass

Scores

CVSS v4 5.3
EPSS 0.0016
EPSS Percentile 5.7%
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (4)
traefik/traefik 3.6.0 - 3.6.23
traefik/traefik 3.6.23
traefik/traefik 3.7.0 - 3.7.7
traefik/traefik 3.7.7
Published Jul 22, 2026
Tracked Since Jul 22, 2026