THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

[GHSA] GHSA-8rxv-jg7p-wvg3 (high) — Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

highgithub_advisoriesPublished 2026-08-06

GHSA-8rxv-jg7p-wvg3 Severity: high CVE: CVE-2026-67309

Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass

## Summary

There is a high severity vulnerability in Traefik's Kubernetes Ingress NGINX provider. When an Ingress uses the `nginx.ingress.kubernetes.io/rewrite-target` annotation with a regular expression that captures attacker-controlled

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-8rxv-jg7p-wvg3