CVE-2026-71327
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.6
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.36%
- CWE
- CWE-694
- Published
- 2026-08-06
- Last modified
- 2026-08-07
Affected products
- traefik traefik
- traefik traefik
Weakness type
Related vulnerabilities
- CVE-2026-57024 — Junos OS: MX with SPC3, SRX Series: Repeated VPN negotiation failures will eventually cause iked to crash continuously
- CVE-2026-5794 — Vulnerability in Cryptobox allows an authenticated user to trigger an account lockout
- CVE-2025-13609 — Keylime: keylime: registrar allows identity takeover via duplicate uuid registration
- CVE-2025-59048 — OpenBao AWS Plugin Vulnerable to Cross-Account IAM Role Impersonation in AWS Auth Method
- CVE-2024-41146 — Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller...
- CVE-2022-23721 — PingID integration for Windows login duplicate username collision.
- CVE-2023-20100 — Cisco IOS XE Software for Wireless LAN Controllers CAPWAP Join Denial of Service Vulnerability
- CVE-2021-3436 — BT: Possible to overwrite an existing bond during keys distribution phase when the identity address of the bond is known