THREAT OPS › Threat News › [GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
[GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
GHSA-8rxv-jg7p-wvg3 Severity: high CVE: CVE-2026-67309
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
## Summary
There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the `nginx.ingress.kubernetes.io/rewrite-target` annotation with a regular expression that captures attacker-controlled
MITRE ATT&CK techniques
Indicators of compromise
- 5c8ff19144683f862c04e8ac01893e8cd94a3519d3d9ca3e6fbd0a7de73261basha256
- b93f02cd07b79490fb8c8f02e301a7a1ec553195sha1
- 69259c3acc9d4bdc065cb2e3b83336f7de3e7038sha1
- CVE-2026-67309cve
- http://127.0.0.1:18080/adminurl
- http://127.0.0.1:18080/api../adminurl
- http://127.0.0.1:18080/api%2e%2e/adminurl
- nginx.ingress.kubernetes.iodomain
- networking.k8s.iodomain
- kubernetes.iodomain
Original source: https://github.com/advisories/GHSA-8rxv-jg7p-wvg3