THREAT OPS › Threat News › [GHSA] GHSA-fgjj-px3w-67xx (high) — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
[GHSA] GHSA-fgjj-px3w-67xx (high) — Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
GHSA-fgjj-px3w-67xx Severity: high CVE: CVE-2026-71327
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
## Summary
There is a high severity vulnerability in Traefik's Kubernetes Gateway API provider. Router and service identities for `HTTPRoute`, `GRPCRoute`, `TCPRoute` and `TLSRoute` objects were built by hyphen-concatenating the route namespace, the route
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- dbd809b1de85d86d0718c80bedbaabd9aebaa3c6697f9e986ab5f387f4196cb7sha256
- CVE-2026-71327cve
- http://127.0.0.1:18080/url
- rbac.authorization.k8s.iodomain
- gateway.networking.k8s.iodomain
- traefik.iodomain
Original source: https://github.com/advisories/GHSA-fgjj-px3w-67xx