CVE-2026-71327
CVE-2026-71327 is a high-severity vulnerability with a CVSS 4.0 base score of 7.6. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-694.
Key facts
- Severity: High (CVSS 4.0 base score 7.6)
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-694
- Published:
- Last modified:
Description
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
Frequently asked questions
- What is CVE-2026-71327?
- Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.
- How severe is CVE-2026-71327?
- CVE-2026-71327 has a CVSS 4.0 base score of 7.6, rated high severity.
- Is CVE-2026-71327 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-71327?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2026-71327 published?
- CVE-2026-71327 was published on 2026-08-06 and last updated on 2026-08-07.
References
- https://github.com/traefik/traefik/commit/a764166656f0cd337f917ac76315c381cca844f9
- https://github.com/traefik/traefik/pull/13580
- https://github.com/traefik/traefik/releases/tag/v3.6.25
- https://github.com/traefik/traefik/releases/tag/v3.7.10
- https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx
Other CWE-694 vulnerabilities
- CVE-2025-13609 — High (CVSS 8.2): A vulnerability has been identified in keylime where an attacker can exploit this flaw by registering a new agent using…
- CVE-2025-59048 — High (CVSS 8.1): OpenBao's AWS Plugin generates AWS access credentials based on IAM policies. Prior to version 0.1.1, the AWS Plugin is…
- CVE-2023-20100 — Medium (CVSS 6.8): A vulnerability in the access point (AP) joining process of the Control and Provisioning of Wireless Access Points…
- CVE-2026-57024 — Medium (CVSS 5.3): A Use of Multiple Resources with Duplicate Identifier vulnerability in the IKE daemon (iked) of Juniper Networks Junos…
- CVE-2026-5794 — Medium (CVSS 4.9): A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by…
- CVE-2024-41146 — Medium (CVSS 4.6): Use of Multiple Resources with Duplicate Identifier (CWE-694) in the Controller 6000 and Controller 7000 Platforms…