<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T16:23:49.737877+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0268</id>
    <title>certfr-2026-avi-0268 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un déni de s…</title>
    <updated>2026-10-04T16:23:49.793885+00:00</updated>
    <content>certfr-2026-avi-0268</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0268"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-275588</id>
    <title>EUVD-2026-275588</title>
    <updated>2026-10-04T16:23:49.793927+00:00</updated>
    <content>EUVD-2026-275588</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-275588"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-29777</id>
    <title>fkie_cve-2026-29777</title>
    <updated>2026-10-04T16:23:49.793942+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can bypass listener hostname constraints and redirect traffic for victim hostnames to attacker-controlled backends. This vulnerability is fixed in 3.6.10.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-29777"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-8q2w-wr49-whqj</id>
    <title>GHSA-8q2w-wr49-whqj — Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values</title>
    <updated>2026-10-04T16:23:49.793975+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik, Go: github.com/traefik/traefik/v2</p>
<p>## Summary</p>
<p>There is a potential vulnerability in Traefik's Kubernetes Gateway provider related to rule injection.</p>
<p>A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can bypass listener hostname constraints and redirect traffic for victim hostnames to attacker-controlled backends.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v3.6.10</p>
<p>## For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p>hey Traefik,</p>
<p>repo: https://github.com/traefik/traefik
commit: a4a91344edcdd6276c1b766ca19ee3f0e346480f (as-of 2026-03-02)</p>
<p>traefik's kubernetes gateway provider builds router rules by interpolating HTTPRoute match values into the traefik rule language using backtick-delimited string literals (e.g., `Header(`name`,`value`)`, `Query(`name`,`value`)`) without escaping or validation.</p>
<p>because backtick is a delimiter in the rule language, a tenant-controlled backtick can terminate the literal and inject additional rule tokens (for example `) || HostRegexp(`.\*`) || ...`). this changes the parsed ast so that an injected OR branch is not gated by the intended `Host(...)` constraint due to operator precedence, and can result in end-to-end routing hijack (victim host…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-8q2w-wr49-whqj"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10385-1</id>
    <title>openSUSE-SU-2026:10385-1 — traefik-3.6.10-2.1 on GA media</title>
    <updated>2026-10-04T16:23:49.794041+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik-3.6.10-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10385-1"/>
  </entry>
</feed>
