CVE-2026-65602 Details
Description
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This is fixed in 3.6.23 and 3.7.7.
A vulnerability exists in Traefik versions 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6, where the crossProviderNamespaces allowlist is not properly enforced for IngressRouteTCP service serversTransport references. This flaw allows a low-privileged Kubernetes user in a namespace not included in the allowlist to manipulate serversTransport settings, leading Traefik to accept prohibited cross-provider references. The issue arises because the allowlist is only applied to HTTP serversTransport references. Exploiting this vulnerability could enable unauthorized access to file-provider TCPServersTransport, including sensitive backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings.
Users can upgrade to Traefik versions 3.6.23 or 3.7.7 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| traefik traefik | >= 3.6.0, < 3.6.23 >= 3.7.0, < 3.7.7 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 6, 2026 | Initial Analysis | [email protected] |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |