CVE-2026-54765Disclosure(traefik / traefik)

LOWCVSS 8.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-07-08: 2Technical Details · 2026-07-08: 207-08
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets1 URL
Full discourse2 posts
  • Mohi@disismohi
    Disclosure

    CVE-2026-54765: @traefik 3.7.0–3.7.5 can apply the wrong HTTPRoute's filters to your traffic. If those filters set tenant IDs or auth headers, one tenant can steal another's context. CVSS 8.5. Here's what to audit Wednesday.

    Post summary

    Traefik versions 3.7.0–3.7.5 are vulnerable to incorrect HTTPRoute filter application, enabling tenants to steal each other’s context (CVSS 8.5); no PoC, exploit code, patch, or active exploitation is reported.

    1001070
    71 followersView on X
  • ThreatAft@ThreatAft
    General

    🚨 CRITICAL: Traefik 3-CVE Cluster — CVSS 10.0 CVE-2026-54763: Header injection bypasses BasicAuth/DigestAuth/ForwardAuth. CVE-2026-54764: ForwardAuth port bypass (8.5) CVE-2026-54765: K8s Gateway context leak (5.8) 🔗 https://threataft.com/articles/traefik-cve-2026-54763-54764-54765-auth-bypass?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Traefik #infosec

    Post summary

    The tweet announces three critical CVEs for Traefik 3, detailing header injection and authentication bypass, but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000060
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more