๐Ÿ” CVE Alert

CVE-2026-71327

UNKNOWN 0.0

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.

CWE CWE-694
Vendor traefik
Product traefik
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for traefik traefik

Be the first to know when new unknown vulnerabilities affecting traefik traefik are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

traefik / traefik
>= 3.0.0, < 3.6.25 >= 3.7.0, < 3.7.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx github.com: https://github.com/traefik/traefik/pull/13580 github.com: https://github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9 github.com: https://github.com/traefik/traefik/releases/tag/v3.6.25 github.com: https://github.com/traefik/traefik/releases/tag/v3.7.10