CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-65601

unknowncovered by 1 sourcefirst seen 2026-07-22
Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace Service could therefore bind a Traefik Middleware from the backend namespace without a separate grant for that middleware, potentially injecting trusted reverse-proxy identity headers into downstream requests. The issue is fixed in version 3.7.7.

⚡ Watch CVE-2026-65601

Get an email if CVE-2026-65601 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (1)

External references

NVD record for CVE-2026-65601

CVE.org record

Embed the live status

CVE-2026-65601 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-65601 status](https://www.csirts.com/badge/CVE-2026-65601)](https://www.csirts.com/cve/CVE-2026-65601)