CVE-2026-71327
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
- Affected products
- Traefik
- Fix
- Available
- CVSS 4.0
- 7.6 HIGH
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-694
- NVD status
- Received
- Published
- 2026-08-06
CVE-2026-71327 at NVD
1 known exploit for CVE-2026-71327
Proof-of-concept code and exploit modules indexed by Sploitus