🛡️ CVE-2026-67309 — traefik
Description
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
Summary
There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the nginx.ingress.kubernetes.io/rewrite-target annotation with a regular expression that captures attacker-controlled text without requiring a path separator (for example path /api(.*) with rewrite target /$1), the generated RewriteTarget middleware can turn an initially safe request path into a dot-segment traversal path after the router has already been selected.
Patches
- https://github.com/traefik/traefik/releases/tag/v3.7.8
For more information
If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
<details>
<summary>Original Description</summary>
Summary
Traefik's Kubernetes Ingress NGINX provider creates an internal RewriteTarget middleware for the nginx.ingress.kubernetes.io/rewrite-target annotation. When an Ingress path captures attacker-controlled text without requiring a path separator, the middleware can turn an initially safe path into a dot-segment traversal path after Traefik has already selected the router.
For example, with Ingress path /api(.*) and rewrite target /$1, an unauthenticated request to /api../admin follows this flow:
1. The default entry-point path sanitizer leaves /api../admin unchanged because api.. is one ordinary segment.
2. The public router's PathRegexp("(?i)^/api(.*)") rule matches.
3. RewriteTarget captures ../admin and creates /../admin.
4. The middleware forwards /../admin without checking whether path normalization changes it.
5. A backend that normalizes paths resolves /../admin to /admin.
6. The request reaches content intended to be reachable only through a separate /admin router with BasicAuth, DigestAuth, or ForwardAuth.
This is an unpatched sibling of [GHSA-cxjq-mrr5-89rv](https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv), which added post-replacement normalization validation to ReplacePathRegex. The separate ingress-nginx RewriteTarget implementation did not receive the same validation. The bypass remains exploitable in the patched Traefik v3.7.7 release.
Severity
Proposed severity: Critical
CVSS 3.1: 9.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- Attack vector: Network
- Attack complexity: Low once the affected routing pattern exists
- Privileges required: None
- User interaction: None
- Scope: Unchanged
- Confidentiality: High
- Integrity: High
- Availability: None
Primary weakness: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)
Secondary weakness: CWE-288 — Authentication Bypass Using an Alternate Path or Channel
The practical impact depends on the protected backend paths. If they are read-only or low sensitivity, environmental severity may be lower.
Exploitation Preconditions
- The Kubernetes Ingress NGINX provider is enabled.
- A public Ingress uses
rewrite-targetwith a regex that can capture..adjacent to the matched prefix, such as/api(.*)with/$1. - A protected router exposes another path on the same backend, such as
/admin, and relies on a Traefik authentication or authorization middleware. - The backend normalizes dot segments before dispatching the request.
These are deployment prerequisites; the remote attacker needs no credentials or special timing.
Affected Components
Confirmed versions
- Traefik v3.7.0 through v3.7.7
- Current
masterat commitb93f02cd07b79490fb8c8f02e301a7a1ec553195 - Current
v3.7branch at69259c3acc9d4bdc065cb2e3b83336f7de3e7038
The vulnerable middleware is present in every stable v3.7 release checked. The v2.11 and v3.6 branches do not contain this ingress-nginx RewriteTarget implementation.
Code locations
pkg/provider/kubernetes/ingress-nginx/middleware.go:257-274- Converts the Ingress path and
rewrite-targetannotation directly intodynamic.RewriteTargetconfiguration. pkg/middlewares/ingressnginx/rewritetarget/rewrite_target.go:85-157- Performs capture-based path rewriting and forwards the rewritten path without normalization validation.
pkg/server/middleware/middlewares.go:346-353- Instantiates the vulnerable middleware in the live HTTP chain.
Root Cause
The provider passes the route regex and annotation replacement into the middleware:
```go
loc.RewriteTarget = &dynamic.RewriteTarget{
Regex: loc.Path,
Replacement: rewrite,
}
```
RewriteTarget.ServeHTTP then derives a path from attacker-controlled capture groups:
```go
newTarget = rt.regexp.ReplaceAllString(currentPath, rt.replacement)
req.URL.RawPath = newTarget
req.URL.Path, err = url.PathUnescape(req.URL.RawPath)
req.RequestURI = req.URL.RequestURI()
rt.next.ServeHTTP(rw, req)
```
There is no invariant check between `Path
How this vulnerability can be exploited
This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality none, integrity none, availability none.
Weakness class
CVE-2026-67309 is classified as CWE-22: Path Traversal. A file path built from user input is not confined to the intended directory, letting an attacker reach files elsewhere on the filesystem.
Affected software
CVE-2026-67309 is recorded against 2 packages.
- github.com/traefik/traefik/v3
- unknown
Timeline and source
Published on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.
References
github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
www.vulncheck.com (Web)
Details
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| github.com/traefik/traefik/v3 | — | — |
| unknown | — | — |
References
Similar Threats
- High CVE-2026-32305
- Low CVE-2026-32595
- Medium CVE-2026-29777
- Medium CVE-2026-26998
- High CVE-2026-26999
More CVE 2026 advisories
Browse all of CVE 2026 in the advisory index.
Site Security Check
Is traefik part of your stack?
CVE-2026-67309 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.