What is CVE-2026-67309?
CVE-2026-67309 is a path traversal vulnerability affecting Traefik versions 3.7.0 through 3.7.7 in the Kubernetes Ingress NGINX provider's RewriteTarget middleware generated from the `nginx.ingress.kubernetes.io/rewrite-target` annotation. An attacker can manipulate file paths by controlling text captured via specially crafted regex in Ingress paths. Users should immediately update to a patched version.
Azərbaycanca: CVE-2026-67309, Traefik-in 3.7.0 ilə 3.7.7 arası versiyalarında Kubernetes Ingress NGINX provayderinin `nginx.ingress.kubernetes.io/rewrite-target` annotasiyası ilə generasiya olunan RewriteTarget middleware-ində yol keçişi (path traversal) zəifliyidir. Təcavüzkar xüsusi hazırlanmış regex ilə idarə etdiyi mətni istifadə edərək sistemdə fayl yolu manipulyasiyası apara bilər. Təsirə məruz qalan versiyaları işlədən istifadəçilər dərhal yeniləmə etməlidir.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
In which Traefik component was CVE-2026-67309 discovered?
The vulnerability was discovered in the RewriteTarget middleware generated from the `nginx.ingress.kubernetes.io/rewrite-target` annotation in the Kubernetes Ingress NGINX provider.
How can an attacker exploit this vulnerability?
An attacker can manipulate file paths by controlling text captured via specially crafted regex.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.