What is CVE-2026-65602?
This vulnerability exists in Traefik versions 3.6.0-3.6.22 and 3.7.0-3.7.6 where the `crossProviderNamespaces` allowlist is not enforced for `IngressRouteTCP` service `serversTransport` references. A low-privileged Kubernetes user in an unlisted namespace can manipulate the `serversTransport` configuration. Affected systems should be updated to a patched version immediately.
Azərbaycanca: Bu boşluq Traefik-in 3.6.0-3.6.22 və 3.7.0-3.7.6 versiyalarında `crossProviderNamespaces` allowlist-in `IngressRouteTCP` üçün tətbiq edilməməsi ilə bağlıdır. Aşağı səlahiyyətli Kubernetes istifadəçisi, allowlist-ə daxil edilməmiş bir namespace-dən `serversTransport` konfiqurasiyasına müdaxilə edə bilər. Təsirə məruz qalan sistemlərdə dərhal Traefik-i yeniləmək tövsiyə olunur.
FAQ2
In which Traefik component is the `crossProviderNamespaces` restriction not properly enforced for CVE-2026-65602?
This vulnerability is related to the `crossProviderNamespaces` allowlist not being enforced for `serversTransport` references in `IngressRouteTCP` services.
What privilege level of Kubernetes user can manipulate the `serversTransport` configuration by exploiting CVE-2026-65602?
A low-privileged Kubernetes user in an unlisted namespace can manipulate the `serversTransport` configuration.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.