Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN757
_____________________________________________________________________


DATE                : 16/07/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running Traefik (Go) versions prior to
                                        3.7.8.
 
=====================================================================

https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3
_____________________________________________________________________


Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows
Route-Level Authentication Bypass

High
kevinpollet published GHSA-8rxv-jg7p-wvg3 Jul 16, 2026

Package
Traefik (Go)

Affected versions
>= v3.7.0, <= v3.7.7

Patched versions
v3.7.8


Description

Summary

There is a high severity vulnerability in Traefik's Kubernetes Ingress
NGINX provider. When an Ingress uses the
nginx.ingress.kubernetes.io/rewrite-target annotation with a regular
expression that captures attacker-controlled text without requiring a
path separator (for example path /api(.*) with rewrite target /$1),
the generated RewriteTarget middleware can turn an initially safe
request path into a dot-segment traversal path after the router has
already been selected.


Patches

    https://github.com/traefik/traefik/releases/tag/v3.7.8

For more information

If you have any questions or comments about this advisory, please
open an issue.

Original Description

Severity
High
7.8/ 10

CVSS v4 base metrics
Exploitability Metrics
Attack Vector Network
Attack Complexity Low
Attack Requirements None
Privileges Required None
User interaction None
Vulnerable System Impact Metrics
Confidentiality None
Integrity None
Availability None
Subsequent System Impact Metrics
Confidentiality High
Integrity High
Availability None
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

CVE ID
No known CVE

Weaknesses
Weakness CWE-22
Weakness CWE-288

Credits

    @B1gN0Se B1gN0Se Reporter


=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




