Use of multiple resources with duplicate identifier in Traefik - CVE-2026-71327
Published: August 21, 2026
Vulnerability details
The vulnerability allows a remote user to redirect traffic to an attacker-controlled backend and disclose sensitive information.
The vulnerability exists due to use of multiple resources with duplicate identifier in the Kubernetes Gateway API provider route identity construction and configuration merge logic when processing accepted HTTPRoute or GRPCRoute objects attached to the same Gateway with equivalent match rules. A remote user can create or modify a colliding Route to redirect traffic to an attacker-controlled backend and disclose sensitive information.
Exploitation requires permission to create or modify a Route accepted by a shared Gateway and a namespace and Route name combination that collides with the victim Route identity.