Use of multiple resources with duplicate identifier in Traefik - CVE-2026-71327

 

Use of multiple resources with duplicate identifier in Traefik - CVE-2026-71327

Published: August 21, 2026


Vulnerability identifier: #VU144547
CSH Severity: Medium
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-71327
CWE-ID: CWE-694
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to redirect traffic to an attacker-controlled backend and disclose sensitive information.

The vulnerability exists due to use of multiple resources with duplicate identifier in the Kubernetes Gateway API provider route identity construction and configuration merge logic when processing accepted HTTPRoute or GRPCRoute objects attached to the same Gateway with equivalent match rules. A remote user can create or modify a colliding Route to redirect traffic to an attacker-controlled backend and disclose sensitive information.

Exploitation requires permission to create or modify a Route accepted by a shared Gateway and a namespace and Route name combination that collides with the victim Route identity.


Affected software

Traefik

How to mitigate CVE-2026-71327

Install security update from vendor's website.

Traefik - addressed in versions 3.6.25, 3.7.10

External References

Related Security Bulletins