{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/traefik--3.7.0--3.7.11/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-88877"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Traefik (\u003e= 3.7.0, \u003c= 3.7.11)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Traefik Labs"],"content_html":"\u003cp\u003eTraefik (versions v3.7.0 through v3.7.11) contains a vulnerability in its Kubernetes ingress-nginx provider that enables an attacker to bypass critical middleware, including authentication (e.g., BasicAuth) and source-IP allowlisting. The issue arises when an Ingress resource is configured with both an authentication annotation and the 'nginx.ingress.kubernetes.io/from-to-www-redirect' annotation.\u003c/p\u003e\n\u003cp\u003eUnder these conditions, the Traefik provider creates a 'sibling' router that matches based on the host alone. By crafting an HTTP request containing a non-numeric or empty port within the 'Host' header (e.g., 'Host: \u003ca href=\"https://www.example.com\"\u003ewww.example.com\u003c/a\u003e:x'), an attacker can cause the load balancer to select this sibling router instead of the intended parent. Because the RedirectRegex middleware used in the redirection pattern is non-terminal, requests that do not trigger a redirect are forwarded directly to the backend without any security middlewares applied. This allows unauthorized access to services intended to be protected by Traefik. The vulnerability is resolved in Traefik v3.7.12.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to bypass access controls and security policies on protected backend services. This exposes sensitive internal APIs or applications to unauthorized interaction, potentially leading to full system compromise depending on the backend service's own security posture.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Traefik to v3.7.12 or later immediately to resolve the insecure router creation logic.\u003c/li\u003e\n\u003cli\u003eAudit existing Ingress configurations for the simultaneous presence of authentication annotations and 'nginx.ingress.kubernetes.io/from-to-www-redirect' for any services exposed via the Kubernetes provider.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous 'Host' headers containing non-numeric port suffixes that may indicate an attempt to probe for this bypass.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T15:08:14Z","date_published":"2026-09-10T15:08:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-traefik-auth-bypass/","summary":"A vulnerability in the Traefik Kubernetes ingress-nginx provider allows unauthenticated access to backend services by bypassing middleware when specific host and annotation configurations are used.","title":"Traefik Kubernetes Provider Authentication Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-traefik-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Traefik (\u003e= 3.7.0, \u003c= 3.7.11)","version":"https://jsonfeed.org/version/1.1"}