CVE-2026-65601

MEDIUM CVSS 4.0: 5.3 EPSS 0.24%
Updated Jul 23, 2026
Kubernetes
Parameter Value
CVSS 5.3 (MEDIUM)
Affected Versions 3.7.0 — 3.7.6
Fixed In 3.7.7
Type CWE-863 (Incorrect Authorization)
Vendor Kubernetes
Public PoC No

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests.

The issue is fixed in version 3.7.7.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
Present
Additional conditions required
Privileges Required
Low
Basic privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
None
No data leak
Integrity
None
No data modification
Availability
None
No disruption

CVSS Vector v4.0