<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T05:47:04.855199+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823</id>
    <title>certfr-2026-avi-0823 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
    <updated>2026-10-04T05:47:04.860572+00:00</updated>
    <content>certfr-2026-avi-0823</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333678</id>
    <title>EUVD-2026-333678</title>
    <updated>2026-10-04T05:47:04.860610+00:00</updated>
    <content>EUVD-2026-333678</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333678"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54765</id>
    <title>fkie_cve-2026-54765</title>
    <updated>2026-10-04T05:47:04.860625+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-54765"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-6p8f-p8j2-rqmv</id>
    <title>GHSA-6p8f-p8j2-rqmv — Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port</title>
    <updated>2026-10-04T05:47:04.860659+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v3</p>
<p>## Summary</p>
<p>There is a medium severity vulnerability in Traefik's Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route's filter set to all requests reaching that backend. In Gateway deployments
where `backendRef` filters set security-sensitive headers — such as tenant identity,
authorization context, or values the backend trusts — an attacker who can create an
accepted HTTPRoute sharing the same backend Service:port may cause their route's filter
context to be applied to another route's requests, potentially crossing namespace
boundaries when a `ReferenceGrant` permits cross-namespace targeting.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v3.7.6</p>
<p>## For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p># Traefik Gateway HTTPRoute backendRef filter context collision across routes sharing Service:port</p>
<p>## Summary</p>
<p>Traefik's Kubernetes Gateway API provider builds the dynamic HTTP backend service key for a Gateway `HTTPRoute` backendRef from only the backend namespace, Service name, protocol, and port. It does not include the HTTPRoute, listener, rule, or backendRef filter identity in that key.</p>
<p>When two accepted HTTPRoutes point to the same bac…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-6p8f-p8j2-rqmv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11251-1</id>
    <title>openSUSE-SU-2026:11251-1 — traefik-3.7.7-1.1 on GA media</title>
    <updated>2026-10-04T05:47:04.860729+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik-3.7.7-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:11251-1"/>
  </entry>
</feed>
