SCA: security update for github.com/traefik/traefik/v3 (GHSA-6p8f-p8j2-rqmv)

medium Tenable Self-Hosted Container Security Plugin ID 445738

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's
Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend
Service:port but configure different backendRef filters to the same child service and apply only one
route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters
set security-sensitive headers, such as tenant identity, authorization context, or values the backend
trusts, an attacker who can create an accepted HTTPRoute sharing the same backend Service:port may cause
their route's filter context to be applied to another route's requests, potentially crossing namespace
boundaries when a ReferenceGrant permits cross-namespace targeting. This issue is fixed in version v3.7.6.
(CVE-2026-54765)

Solution

Update the github.com/traefik/traefik/v3 library and its related packages to version 3.7.6 or later.

See Also

https://github.com/advisories/GHSA-6p8f-p8j2-rqmv

Plugin Details

Severity: Medium

ID: 445738

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/6/2026

Updated: 8/6/2026

Risk Information

VPR

Risk Factor: Low

Score: 3.9

Percentile: 52.79

Vendor

Vendor Severity: Medium

CVSS v2

Risk Factor: High

Base Score: 7.5

Temporal Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:C/A:N

CVSS Score Source: CVE-2026-54765

CVSS v3

Risk Factor: High

Base Score: 8.5

Temporal Score: 7.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 2.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:N/SC:L/SI:H/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 7/4/2026

Reference Information

CVE: CVE-2026-54765