High severity8.1GHSA Advisory· Published Aug 6, 2026· Updated Sep 16, 2026
CVE-2026-71327
CVE-2026-71327
Description
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/traefik/traefik/v3Go | >= 3.0.0, < 3.6.25 | 3.6.25 |
github.com/traefik/traefik/v3Go | >= 3.7.0, < 3.7.10 | 3.7.10 |
Affected products
3- osv-coordsRange: < 0.0.20260827T195228-160000.1.1
Patches
Vulnerability mechanics
References
6- github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9nvdPatchWEB
- github.com/traefik/traefik/pull/13580nvdIssue TrackingPatchWEB
- github.com/traefik/traefik/releases/tag/v3.6.25nvdPatchRelease NotesWEB
- github.com/traefik/traefik/releases/tag/v3.7.10nvdPatchRelease NotesWEB
- github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xxnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-fgjj-px3w-67xxghsaADVISORY
News mentions
0No linked articles in our index yet.