Dev.to Security 🔐 Cybersecurity 👁 0 📖 2 min read

CVE-2026-65602: CVE-2026-65602: IngressRouteTCP ServersTransport Namespace Bypass in Traefik

CVE-2026-65602: IngressRouteTCP ServersTransport Namespace Bypass in Traefik Vulnerability ID: CVE-2026-65602 CVSS Score: 5.3 Published: 2026-08-05 An authorization bypass vulnerability in Traefik allows low-privile

CVE-2026-65602: IngressRouteTCP ServersTransport Namespace Bypass in Traefik

Vulnerability ID: CVE-2026-65602
CVSS Score: 5.3
Published: 2026-08-05

An authorization bypass vulnerability in Traefik allows low-privileged users within unauthorized Kubernetes namespaces to reference privileged file-provider TCP serversTransports via IngressRouteTCP resources, bypassing the crossProviderNamespaces constraint.

TL;DR

Traefik fails to validate the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport configurations, enabling cross-provider namespace bypass.

Technical Details

  • CWE ID: CWE-863 (Incorrect Authorization)
  • Attack Vector: Network (Remote)
  • CVSS v4.0: 5.3 (Medium)
  • Impact Type: Subsequent System Integrity and Confidentiality (High)
  • Exploit Status: No public weaponized exploits or active exploitation reported
  • Mitre ATT&CK Technique: T1068 (Exploitation for Privilege Escalation)

Affected Systems

  • Traefik reverse proxy deployments running within Kubernetes clusters using IngressRouteTCP CRDs.
  • Traefik: >= 3.6.0, <= 3.6.22 (Fixed in: 3.6.23)
  • Traefik: >= 3.7.0, <= 3.7.6 (Fixed in: 3.7.7)

Code Analysis

Commit: 67501cb

Restricts serverTransport cross-provider lookup in TCP provider parsing

@@ -15,5 +15,9 @@
    if strings.Contains(serversTransportName, providerNamespaceSeparator) {
        if !p.AllowCrossNamespace && strings.HasSuffix(serversTransportName, providerNamespaceSeparator+providerName) {
            return "", fmt.Errorf("invalid reference to serversTransport %s: namespace-name@kubernetescrd format is not allowed when crossnamespace is disallowed", serversTransportName)
        }
+       if !isCrossProviderNamespaceAllowed(p.CrossProviderNamespaces, parentNamespace) {
+           return "", fmt.Errorf("serversTransport %q reference is not allowed: namespace %q is not in crossProviderNamespaces", serversTransportName, parentNamespace)
+       }
        return serversTransportName, nil
    }

Commit: 26c96a3

Preparation commit for Traefik releases addressing namespace validation vulnerabilities

Mitigation Strategies

  • Enforce explicit crossProviderNamespaces restrictions in static configurations.
  • Perform periodic scans on custom resource definitions to identify unauthorized provider suffixes.
  • Segregate administrative and untrusted workloads into isolated Kubernetes cluster deployments.

Remediation Steps:

  1. Identify the current active Traefik deployment version.
  2. Upgrade to Traefik v3.6.23 or v3.7.7 depending on the active branch.
  3. Verify the static configuration explicitly includes the crossProviderNamespaces list containing only trusted namespaces.
  4. Run the kubectl diagnostic command to audit active IngressRouteTCP resources.

References

Read the full report for CVE-2026-65602 on our website for more details including interactive diagrams and full exploit analysis.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.