Database/Container, Kubernetes & orchestration
Traefik: A tenant with HTTPRoute creation rights exposes the REST provider handler, bypassing provider isolation
CVSS 6.4CVE-2026-44774Container, Kubernetes & orchestrationcurated
Impact
A tenant with HTTPRoute creation rights exposes the REST provider handler, bypassing provider isolation
Who can reach it
Cluster user with namespace access
What to do
Rolling Traefik upgrade
References
Related entries
- Traefik: A tenant with HTTPRoute write access injects backtick-delimited rule tokens into Traefik's routerCVE-2026-29777 · TraefikMedium
- Traefik: Cross-namespace isolation not enforced in the Kubernetes CRD providerCVE-2026-41174 · TraefikMedium
- Traefik: Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backendCVE-2024-45410 · TraefikCritical
- Traefik: Path matcher flaw in PathPrefix/Path/PathRegex routing enables route and authorization bypassCVE-2025-32431 · TraefikHigh
- Traefik: mTLS bypass via SNI pre-sniffing on fragmented ClientHello packetsCVE-2026-32305 · TraefikHigh
- Traefik: Authentication bypass in ForwardAuth when trustForwardHeader=falseCVE-2026-35051 · TraefikHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.