<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:54:30 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0823 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un contourne…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823</link>
      <description>certfr-2026-avi-0823</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0823</guid>
    </item>
    <item>
      <title>EUVD-2026-333678</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-333678</link>
      <description>EUVD-2026-333678</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-333678</guid>
    </item>
    <item>
      <title>fkie_cve-2026-54765</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-54765</link>
      <description>&lt;p&gt;Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik&amp;#39;s Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route&amp;#39;s filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route&amp;#39;s filter context to be applied to another route&amp;#39;s requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik&amp;#39;s Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route&amp;#39;s filter set to all requests reaching that backend. In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route&amp;#39;s filter context to be applied to another route&amp;#39;s requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-54765</guid>
    </item>
    <item>
      <title>GHSA-6p8f-p8j2-rqmv — Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-6p8f-p8j2-rqmv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a medium severity vulnerability in Traefik&amp;#39;s Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route&amp;#39;s filter set to all requests reaching that backend. In Gateway deployments
where `backendRef` filters set security-sensitive headers — such as tenant identity,
authorization context, or values the backend trusts — an attacker who can create an
accepted HTTPRoute sharing the same backend Service:port may cause their route&amp;#39;s filter
context to be applied to another route&amp;#39;s requests, potentially crossing namespace
boundaries when a `ReferenceGrant` permits cross-namespace targeting.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v3.7.6&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Traefik Gateway HTTPRoute backendRef filter context collision across routes sharing Service:port&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s Kubernetes Gateway API provider builds the dynamic HTTP backend service key for a Gateway `HTTPRoute` backendRef from only the backend namespace, Service name, protocol, and port. It does not include the HTTPRoute, listener, rule, or backendRef filter identity in that key.&lt;/p&gt;
&lt;p&gt;When two accepted HTTPRoutes point to the same bac…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a medium severity vulnerability in Traefik&amp;#39;s Kubernetes Gateway API provider.
When two accepted HTTPRoutes target the same backend Service:port but configure different
`backendRef` filters, Traefik may resolve both routes to the same child service and apply
only one route&amp;#39;s filter set to all requests reaching that backend. In Gateway deployments
where `backendRef` filters set security-sensitive headers — such as tenant identity,
authorization context, or values the backend trusts — an attacker who can create an
accepted HTTPRoute sharing the same backend Service:port may cause their route&amp;#39;s filter
context to be applied to another route&amp;#39;s requests, potentially crossing namespace
boundaries when a `ReferenceGrant` permits cross-namespace targeting.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v3.7.6&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Traefik Gateway HTTPRoute backendRef filter context collision across routes sharing Service:port&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s Kubernetes Gateway API provider builds the dynamic HTTP backend service key for a Gateway `HTTPRoute` backendRef from only the backend namespace, Service name, protocol, and port. It does not include the HTTPRoute, listener, rule, or backendRef filter identity in that key.&lt;/p&gt;
&lt;p&gt;When two accepted HTTPRoutes point to the same bac…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-6p8f-p8j2-rqmv</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11251-1 — traefik-3.7.7-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11251-1</link>
      <description>&lt;p&gt;traefik-3.7.7-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;traefik-3.7.7-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11251-1</guid>
    </item>
  </channel>
</rss>
