—
GO-2026-6207
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
Quick fix
GO-2026-6207 — github.com/traefik/traefik/v3: upgrade to the fixed version with the command below.
go get github.com/traefik/traefik/v3@v3.7.8Details
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/traefik/traefik
Introduced in:
0No fixed version published yet for github.com/traefik/traefik (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/traefik/traefik/v2
Introduced in:
0No fixed version published yet for github.com/traefik/traefik/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/traefik/traefik/v3
Introduced in:
3.7.0Fixed in: 3.7.8Fix
go get github.com/traefik/traefik/v3@v3.7.8References
- https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-67309[ADVISORY]
- https://github.com/traefik/traefik/commit/759515bec1b9f628b21ea8968ef63da853be5e29[FIX]
- https://www.vulncheck.com/advisories/traefik-path-traversal-via-rewritetarget-authentication-bypass[WEB]