๐Ÿ” CVE Alert

CVE-2026-67309

UNKNOWN 0.0

Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker-controlled text without requiring a path separator (e.g., path /api(.*) with rewrite target /$1), a crafted request such as /api../admin matches the public router, is rewritten to a dot-segment traversal path (/../admin), and is forwarded without post-replacement normalization validation. A backend that normalizes dot segments resolves the path to a protected endpoint (e.g., /admin) reachable only through a separate router secured with BasicAuth, DigestAuth, or ForwardAuth, resulting in route-level authentication bypass. The issue is fixed in v3.7.8.

CWE CWE-22
Vendor traefik
Product traefik
Published Aug 1, 2026
Stay Ahead of the Next One

Get instant alerts for traefik traefik

Be the first to know when new unknown vulnerabilities affecting traefik traefik are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

traefik / traefik
3.7.0 < *

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3 github.com: https://github.com/traefik/traefik/commit/b93f02cd07b79490fb8c8f02e301a7a1ec553195 github.com: https://github.com/traefik/traefik/commit/69259c3acc9d4bdc065cb2e3b83336f7de3e7038 vulncheck.com: https://www.vulncheck.com/advisories/traefik-path-traversal-via-rewritetarget-authentication-bypass

Credits

๐Ÿ” B1gN0Se