THREAT OPS › Threat News › [NVD] CVE-2026-67309 — Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker
[NVD] CVE-2026-67309 — Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker
CVE-2026-67309 CVSS: None Published: 2026-08-01T13:17:00.703
Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker-controlled text without requiring a path separator (e.g.
Indicators of compromise
- CVE-2026-67309cve
- nginx.ingress.kubernetes.iodomain
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-67309