EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in Traefik, an open source HTTP reverse proxy and load balancer, affecting versions 2.11.52 and below, 3.6.23 and below, and 3.7.8 and below. The vulnerabilities include cross-user response poisoning, authenticated identity spoofing, and cross-namespace backend hijacking, which can lead to unauthorized access to sensitive data and systems. These vulnerabilities pose a significant business risk and impact, as they can compromise the security and integrity of an organization's infrastructure and data.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
Multiple security vulnerabilities have been identified in Traefik, an open source HTTP reverse proxy and load balancer, affecting versions 2.11.52 and below, 3.6.23 and below, and 3.7.8 and below. The vulnerabilities include cross-user response poisoning, authenticated identity spoofing, and cross-namespace backend hijacking, which can lead to unauthorized access to sensitive data and systems. These vulnerabilities pose a significant business risk and impact, as they can compromise the security and integrity of an organization's infrastructure and data.[emaillocker id="1283"]
• CVE-2026-71324 with a CVSS score of 7.5 – This vulnerability allows an unauthenticated attacker to make a different client read the attacker's smuggled response, which can include authenticated or private content from another request. The attacker can exploit this by making a client open an HTTP/2 or HTTP/3 CONNECT request.
• CVE-2026-71326 with a CVSS score of 3.0 – This vulnerability allows an attacker who has a valid credential and the stored hash to authenticate as an unconfigured username when headerField trusts the forwarded identity. The attacker can exploit this by selecting a password that collides with the singleflight key.
• CVE-2026-71327 with a CVSS score of 8.2 – This vulnerability allows a tenant able to create an accepted Route in a colliding namespace/name combination to redirect another namespace's traffic to a backend it controls. The attacker can exploit this by creating a Route with a name that collides with another namespace's Route.
The identified vulnerabilities pose a significant risk to organizations using Traefik, as they can be exploited to gain unauthorized access to sensitive data and systems. If exploited, these vulnerabilities can lead to serious business consequences, including data breaches, financial losses, and reputational damage. Organizations should be aware of the potential risks and take immediate action to address these vulnerabilities.
RECOMMENDATION:
REFERENCES:
The following reports contain further technical details:
https://github.com/advisories/GHSA-3ccp-42pg-hgv6
https://github.com/advisories/GHSA-6765-c87h-8mrf
https://github.com/advisories/GHSA-fgjj-px3w-67xx
https://github.com/advisories/GHSA-3q9r-p662-5j8m
https://github.com/advisories/GHSA-62fc-8686-hfmq