THREAT OPS › Threat News › [GHSA] GHSA-qq9q-x9w4-chhj (medium) — Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
[GHSA] GHSA-qq9q-x9w4-chhj (medium) — Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
GHSA-qq9q-x9w4-chhj Severity: medium CVE: CVE-2026-65601
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion
## Summary
There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute`
Indicators of compromise
- 26c96a3935cafb473f4a5bae1886560d9aa4e4f0sha1
- CVE-2026-65601cve
- http://attacker.example/url
- discovery.k8s.iodomain
- kubernetes.iodomain
- gateway.networking.k8s.iodomain
- traefik.iodomain
- k8s.iodomain
Original source: https://github.com/advisories/GHSA-qq9q-x9w4-chhj