—
GO-2026-5083
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services in github.com/traefik/traefik
Details
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services in github.com/traefik/traefik
Are you affected?
Enter the version of the package you're using.
Affected packages
Go / github.com/traefik/traefik
Introduced in:
0 No fixed version published yet for github.com/traefik/traefik (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/traefik/traefik/v2
Introduced in:
0 No fixed version published yet for github.com/traefik/traefik/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go / github.com/traefik/traefik/v3
Introduced in:
0 Fixed in: 3.6.21 Fix
go get github.com/traefik/traefik/v3@v3.6.21