
CVE-2026-54765: @traefik 3.7.0–3.7.5 can apply the wrong HTTPRoute's filters to your traffic. If those filters set tenant IDs or auth headers, one tenant can steal another's context. CVSS 8.5. Here's what to audit Wednesday.
Post summary
Traefik versions 3.7.0–3.7.5 are vulnerable to incorrect HTTPRoute filter application, enabling tenants to steal each other’s context (CVSS 8.5); no PoC, exploit code, patch, or active exploitation is reported.

