What is CVE-2026-65601?
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. The issue occurs when resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, where Traefik incorrectly uses the backend Service namespace instead of the HTTPRoute namespace. Users should upgrade to the latest patched version to mitigate the risk.
Azərbaycanca: Traefik-in 3.7.0-dən 3.7.6-ya qədər versiyalarında Kubernetes Gateway API provider-da namespace confusion zəifliyi aşkarlanıb. Bu, HTTPRoute qaydalarında extensionRef həlli zamanı HTTPRoute namespace-i əvəzinə backend Service namespace-inin istifadəsi səbəbindən baş verir. Təsirə məruz qalan sistemlərdə Traefik-i ən son versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of Traefik are affected by the CVE-2026-65601 namespace confusion vulnerability?
Traefik versions 3.7.0 through 3.7.6 are affected by this vulnerability.
What is the recommended mitigation for this vulnerability?
Users should upgrade to the latest patched version of Traefik to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.