—
GO-2026-6192
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
Quick fix
GO-2026-6192 — github.com/traefik/traefik/v3: upgrade to the fixed version with the command below.
go get github.com/traefik/traefik/v3@v3.6.23Details
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/traefik/traefik
Introduced in:
0No fixed version published yet for github.com/traefik/traefik (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/traefik/traefik/v2
Introduced in:
0No fixed version published yet for github.com/traefik/traefik/v2 (go modules). Pin to a known-safe version or switch to an alternative.
Go/github.com/traefik/traefik/v3
Introduced in:
3.6.0Fixed in: 3.6.23Fix
go get github.com/traefik/traefik/v3@v3.6.23References
- https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv[ADVISORY]
- https://nvd.nist.gov/vuln/detail/CVE-2026-65602[ADVISORY]
- https://github.com/traefik/traefik/commit/67501cbe7bc7774e26ecbd1c29af97f098e14b0b[FIX]
- https://github.com/traefik/traefik/pull/13458[FIX]
- https://github.com/traefik/traefik/releases/tag/v3.6.23[WEB]
- https://github.com/traefik/traefik/releases/tag/v3.7.7[WEB]
- https://www.vulncheck.com/advisories/traefik-before-ingressroutetcp-serverstransport-namespace-bypass[WEB]