High [CVE-2026-54765] Unauthorized filter context application in Kubernetes Gateway API provider
This high-severity Red Hat Linux advisory covers CVE-2026-54765 affecting Red Hat OpenShift Dev Spaces.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend.
In Gateway deployments where backendRef filters set security-sensitive headers, such as tenant identity, authorization context, or values the backend trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause their route's filter context to be applied to another route's requests, potentially crossing namespace boundaries when a ReferenceGrant permits cross-namespace targeting.
This issue is fixed in version v3.7.6. The system may incorrectly apply the attacker's route filter context to another route's requests, potentially allowing unauthorized access or information disclosure across different namespaces.
This could lead to the application of security-sensitive headers from the attacker's route to legitimate requests, bypassing intended security controls. This Moderate flaw in Traefik's Kubernetes Gateway API provider, as deployed in Red Hat OpenShift Dev Spaces, could allow an attacker to apply their route's filter context to other requests.
- < 7.0
- < 7.6
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Mitigation
Upgrade to a fixed release: 3.7.6. That is the remediation for this advisory.
The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.
Official advisory · high-confidence parse· fetched 15 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.