Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-65601: CVE-2026-65601: Namespace Confusion Vulnerability in Traefik Gateway API HTTPRoute BackendRef ExtensionRef Resolution

CVE-2026-65601: Namespace Confusion Vulnerability in Traefik Gateway API HTTPRoute BackendRef ExtensionRef Resolution Vulnerability ID: CVE-2026-65601 CVSS Score: 5.3 Published: 2026-08-05 CVE-2026-65601 is a critic

CVE-2026-65601: Namespace Confusion Vulnerability in Traefik Gateway API HTTPRoute BackendRef ExtensionRef Resolution

Vulnerability ID: CVE-2026-65601
CVSS Score: 5.3
Published: 2026-08-05

CVE-2026-65601 is a critical security vulnerability within Traefik's implementation of the Kubernetes Gateway API. Due to variable reuse and incorrect namespace resolution logic in the routing engine, Traefik resolved custom extension filters (such as Traefik CRD Middlewares) inside a target backend service's namespace rather than the originating HTTPRoute's namespace. This flaw enables a low-privileged tenant to bypass namespace isolation boundaries and invoke highly privileged middleware components in foreign namespaces to which they only have service-level routing access.

TL;DR

Traefik versions 3.7.0 through 3.7.6 are vulnerable to namespace confusion where backend-level custom filters (ExtensionRefs) are resolved using the backend service's namespace instead of the source HTTPRoute's namespace, permitting cross-namespace middleware hijacking.

Technical Details

  • CWE ID: CWE-863 (Incorrect Authorization)
  • Attack Vector: Network
  • CVSS v4.0 Score: 5.3 (Medium)
  • EPSS Score: 0.00238
  • Exploit Status: None
  • CISA KEV Status: Not Listed

Affected Systems

  • Traefik Labs Traefik (Kubernetes Gateway API Provider)
  • Traefik: >= 3.7.0, <= 3.7.6 (Fixed in: 3.7.7)

Code Analysis

Commit: 655d632

Fix: use route namespace instead of target service namespace when loading backend-level middlewares in HTTPRoute.

@@ -281,7 +281,7 @@
    middlewares, err := p.loadMiddlewares(conf, namespace, serviceName, backendRef.Filters, pathMatch)
+   middlewares, err := p.loadMiddlewares(conf, route.Namespace, serviceName, backendRef.Filters, pathMatch)

Commit: 26c96a3

Complementary security adjustments to resolve namespace confusion in Gateway API references.

Mitigation Strategies

  • Upgrade Traefik instances to patched version 3.7.7.
  • Audit and restrict Kubernetes Gateway API ReferenceGrant resources to trusted namespaces only.
  • Implement Kyverno or OPA Gatekeeper policies to block cross-namespace HTTPRoutes using ExtensionRef filters.

Remediation Steps:

  1. Identify all running Traefik deployments in the cluster utilizing the Gateway API provider.
  2. Update the Traefik container image tags to 3.7.7 in the respective deployment manifests or Helm values files.
  3. Apply the updated configuration using kubectl or GitOps pipelines to perform a rolling restart.
  4. Verify that the Traefik controller logs indicate version 3.7.7 is active and processing configurations without namespace resolution errors.

References

Read the full report for CVE-2026-65601 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.