🛡️ CVE-2026-67309 — traefik

🟠 CVSS 8.0 — High ✅ No Known Exploit CWE-22 NVD
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

Summary

There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the nginx.ingress.kubernetes.io/rewrite-target annotation with a regular expression that captures attacker-controlled text without requiring a path separator (for example path /api(.*) with rewrite target /$1), the generated RewriteTarget middleware can turn an initially safe request path into a dot-segment traversal path after the router has already been selected.

Patches

  • https://github.com/traefik/traefik/releases/tag/v3.7.8

For more information

If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).

<details>

<summary>Original Description</summary>

Summary

Traefik's Kubernetes Ingress NGINX provider creates an internal RewriteTarget middleware for the nginx.ingress.kubernetes.io/rewrite-target annotation. When an Ingress path captures attacker-controlled text without requiring a path separator, the middleware can turn an initially safe path into a dot-segment traversal path after Traefik has already selected the router.

For example, with Ingress path /api(.*) and rewrite target /$1, an unauthenticated request to /api../admin follows this flow:

1. The default entry-point path sanitizer leaves /api../admin unchanged because api.. is one ordinary segment.

2. The public router's PathRegexp("(?i)^/api(.*)") rule matches.

3. RewriteTarget captures ../admin and creates /../admin.

4. The middleware forwards /../admin without checking whether path normalization changes it.

5. A backend that normalizes paths resolves /../admin to /admin.

6. The request reaches content intended to be reachable only through a separate /admin router with BasicAuth, DigestAuth, or ForwardAuth.

This is an unpatched sibling of [GHSA-cxjq-mrr5-89rv](https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv), which added post-replacement normalization validation to ReplacePathRegex. The separate ingress-nginx RewriteTarget implementation did not receive the same validation. The bypass remains exploitable in the patched Traefik v3.7.7 release.

Severity

Proposed severity: Critical

CVSS 3.1: 9.1 — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

  • Attack vector: Network
  • Attack complexity: Low once the affected routing pattern exists
  • Privileges required: None
  • User interaction: None
  • Scope: Unchanged
  • Confidentiality: High
  • Integrity: High
  • Availability: None

Primary weakness: CWE-22 — Improper Limitation of a Pathname to a Restricted Directory (Path Traversal)

Secondary weakness: CWE-288 — Authentication Bypass Using an Alternate Path or Channel

The practical impact depends on the protected backend paths. If they are read-only or low sensitivity, environmental severity may be lower.

Exploitation Preconditions

  • The Kubernetes Ingress NGINX provider is enabled.
  • A public Ingress uses rewrite-target with a regex that can capture .. adjacent to the matched prefix, such as /api(.*) with /$1.
  • A protected router exposes another path on the same backend, such as /admin, and relies on a Traefik authentication or authorization middleware.
  • The backend normalizes dot segments before dispatching the request.

These are deployment prerequisites; the remote attacker needs no credentials or special timing.

Affected Components

Confirmed versions

  • Traefik v3.7.0 through v3.7.7
  • Current master at commit b93f02cd07b79490fb8c8f02e301a7a1ec553195
  • Current v3.7 branch at 69259c3acc9d4bdc065cb2e3b83336f7de3e7038

The vulnerable middleware is present in every stable v3.7 release checked. The v2.11 and v3.6 branches do not contain this ingress-nginx RewriteTarget implementation.

Code locations

  • pkg/provider/kubernetes/ingress-nginx/middleware.go:257-274
  • Converts the Ingress path and rewrite-target annotation directly into dynamic.RewriteTarget configuration.
  • pkg/middlewares/ingressnginx/rewritetarget/rewrite_target.go:85-157
  • Performs capture-based path rewriting and forwards the rewritten path without normalization validation.
  • pkg/server/middleware/middlewares.go:346-353
  • Instantiates the vulnerable middleware in the live HTTP chain.

Root Cause

The provider passes the route regex and annotation replacement into the middleware:

```go

loc.RewriteTarget = &dynamic.RewriteTarget{

Regex: loc.Path,

Replacement: rewrite,

}

```

RewriteTarget.ServeHTTP then derives a path from attacker-controlled capture groups:

```go

newTarget = rt.regexp.ReplaceAllString(currentPath, rt.replacement)

req.URL.RawPath = newTarget

req.URL.Path, err = url.PathUnescape(req.URL.RawPath)

req.RequestURI = req.URL.RequestURI()

rt.next.ServeHTTP(rw, req)

```

There is no invariant check between `Path

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is low, an attacker needs no privileges on the target. No user interaction is required. Rated impact: confidentiality none, integrity none, availability none.

Weakness class

CVE-2026-67309 is classified as CWE-22: Path Traversal. A file path built from user input is not confined to the intended directory, letting an attacker reach files elsewhere on the filesystem.

Affected software

CVE-2026-67309 is recorded against 2 packages.

  • github.com/traefik/traefik/v3
  • unknown

Timeline and source

Published on 6 August 2026. No public exploit is currently recorded for this entry. Record sourced from NVD.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)
www.vulncheck.com (Web)

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
CWE CWE-22
Public Exploit ✅ No
Source NVD
Published 2026-08-06
Updated 2026-08-12
Modified 2026-08-06
Fix URL N/A

Affected Packages

Software From version Fixed in
github.com/traefik/traefik/v3
unknown

Similar Threats

Site Security Check

Is traefik part of your stack?

CVE-2026-67309 is rated CVSS 8.0 High. BotEraser scans your installation against known CVE records and tells you whether this vulnerability applies to the versions you actually run.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.