CVE-2026-44774 Details
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider accepts any TraefikService backend reference whose name ends with @internal, making it possible to route traffic to rest@internal in addition to the intended api@internal. In shared Gateway deployments where the REST provider is enabled, this allows a low-privileged actor to gain live dynamic configuration write access to Traefik, enabling unauthorized reconfiguration of routers and services. This vulnerability is fixed in 2.11.46, 3.6.17, and 3.7.1.
A vulnerability exists in Traefik's Kubernetes Gateway API provider, allowing a tenant with HTTPRoute creation permissions to expose the REST provider handler. This bypasses the providers.rest.insecure=false setting. The vulnerability is present in Traefik versions prior to 2.11.46, 3.6.17, and 3.7.1. The issue arises because the Gateway provider accepts any TraefikService backend reference ending with @internal, enabling routing to rest@internal alongside the intended api@internal. In shared Gateway deployments with the REST provider enabled, this vulnerability allows a low-privileged actor to access live dynamic configuration write capabilities, facilitating unauthorized reconfiguration of routers and services.
Users can upgrade to Traefik versions 2.11.46, 3.6.17, or 3.7.1 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 16, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:36820 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-44774 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2477937 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-44774.json | redhat-SADP | |
| https://github.com/traefik/traefik/releases/tag/v2.11.46 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/releases/tag/v3.6.17 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/releases/tag/v3.7.1 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/security/advisories/GHSA-96qj-4jj5-wcjc | [email protected] | ExploitPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-15 | External Control of System or Configuration Setting | redhat-SADP |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| traefik traefik | < 2.11.46 >= 3.0.0, < 3.6.17 >= 3.7.0, < 3.7.1 |
CPE
Remediation
| |
Change History
7 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jul 9, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| May 19, 2026 | Initial Analysis | [email protected] |
| May 15, 2026 | New CVE Received | [email protected] |