THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qq9q-x9w4-chhj (medium) — Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

[GHSA] GHSA-qq9q-x9w4-chhj (medium) — Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

highgithub_advisoriesPublished 2026-08-05

GHSA-qq9q-x9w4-chhj Severity: medium CVE: CVE-2026-65601

Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion

## Summary

There is a medium-severity namespace-confusion vulnerability in Traefik's Kubernetes Gateway API provider. When resolving `HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef`, Traefik used the backend Service namespace instead of the `HTTPRoute`

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qq9q-x9w4-chhj