Database/Container, Kubernetes & orchestration
Traefik: A tenant with HTTPRoute write access injects backtick-delimited rule tokens into Traefik's router
CVSS 6.1CVE-2026-29777Container, Kubernetes & orchestrationcurated
Impact
A tenant with HTTPRoute write access injects backtick-delimited rule tokens into Traefik's router rule language; cross-tenant route hijack
Who can reach it
Cluster user with namespace access
What to do
Rolling Traefik upgrade to 3.6.10+
References
Related entries
- Traefik: Cross-namespace isolation not enforced in the Kubernetes CRD providerCVE-2026-41174 · TraefikMedium
- Traefik: Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backendCVE-2024-45410 · TraefikCritical
- Traefik: Path matcher flaw in PathPrefix/Path/PathRegex routing enables route and authorization bypassCVE-2025-32431 · TraefikHigh
- Traefik: mTLS bypass via SNI pre-sniffing on fragmented ClientHello packetsCVE-2026-32305 · TraefikHigh
- Traefik: Authentication bypass in ForwardAuth when trustForwardHeader=falseCVE-2026-35051 · TraefikHigh
- Traefik: Authentication bypass in ForwardAuth and snippet-based auth middlewareCVE-2026-39858 · TraefikHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.