PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-65602 traefik CVE debrief

Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references. A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCPServersTransport — including privileged backend mTLS client certificates, SPIFFE identity, or PROXY-protocol settings. This vulnerability allows a low-privileged Kubernetes user to bypass the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references.

Vendor
traefik
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 should review and update their configurations to ensure that only authorized namespaces are allowed to use the serversTransport feature. This includes administrators, security teams, and operators who manage Traefik deployments.

Technical summary

The Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 versions have a vulnerability that allows a low-privileged Kubernetes user to bypass the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references. This can lead to the use of forbidden cross-provider references and potentially allow access to sensitive information or configurations. The vulnerability is caused by a failure to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references.

Defensive priority

Medium

Recommended defensive actions

  • Review and update Traefik configurations to ensure that only authorized namespaces are allowed to use the serversTransport feature.
  • Implement additional monitoring and logging to detect potential exploitation attempts.
  • Consider upgrading to Traefik 3.6.23 or 3.7.7, which fixes this vulnerability.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

The CVE record was published on 2026-07-22T12:18:20.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. This information is based on the CVE record and NVD entry. Further verification is recommended to ensure accuracy.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-22T12:18:20.560Z and has not been modified since then. The NVD entry is currently Undergoing Analysis.