High severity8.8OSV Advisory· Published Jul 22, 2026· Updated Aug 6, 2026
CVE-2026-65602
CVE-2026-65602
Description
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/traefik/traefik/v3Go | >= 3.6.0, < 3.6.23 | 3.6.23 |
github.com/traefik/traefik/v3Go | >= 3.7.0, < 3.7.7 | 3.7.7 |
Affected products
4- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
9- github.com/traefik/traefik/commit/26c96a3935cafb473f4a5bae1886560d9aa4e4f0nvdPatch
- github.com/advisories/GHSA-42cj-m3vj-89wvghsaADVISORY
- github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wvnvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2026-65602ghsaADVISORY
- www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypassnvdThird Party AdvisoryWEB
- github.com/traefik/traefik/commit/67501cbe7bc7774e26ecbd1c29af97f098e14b0bghsaWEB
- github.com/traefik/traefik/pull/13458ghsaWEB
- github.com/traefik/traefik/releases/tag/v3.6.23ghsaWEB
- github.com/traefik/traefik/releases/tag/v3.7.7ghsaWEB
News mentions
1- Traefik: Critical Auth Bypass & Privilege Escalation Flaws Disclosed TogetherVypr Intelligence · Jul 22, 2026