LIVE · cybersecurity feed
Live wire
cve recordmedium

CVE-2026-29777

traefik · traefik

Published
CVSS6.5
Severitymedium
WeaknessCWE-74
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Description

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match values. In shared gateway deployments, this can bypass listener hostname constraints and redirect traffic for victim hostnames to attacker-controlled backends. This vulnerability is fixed in 3.6.10.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-29777

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-29777.