CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-67309

CVE-2026-67309: Path Traversal and Authentication Bypass in Traefik RewriteTarget Middleware

Alon Barad
Alon Barad
Software Engineer

Aug 6, 2026·7 min read·24 visits

Executive Summary (TL;DR)

Unauthenticated remote attackers can bypass Traefik's routing-layer security controls via relative dot-segment path traversals, gaining unauthorized access to restricted downstream backend resources.

A high-severity path traversal vulnerability exists in Traefik's Kubernetes Ingress NGINX provider. The flaw resides in the RewriteTarget middleware, which is auto-generated when an Ingress resource specifies the `nginx.ingress.kubernetes.io/rewrite-target` annotation. This allows remote, unauthenticated attackers to bypass route-level authentication and access restricted downstream endpoints by exploiting a parser differential.

Vulnerability Overview

Traefik is an open-source reverse proxy and edge router frequently deployed in Kubernetes environments as an Ingress Controller. In this deployment model, Traefik interfaces directly with the Kubernetes API to dynamically translate Ingress resources into internal routing rules. One such translation involves processing NGINX-specific ingress annotations, notably the nginx.ingress.kubernetes.io/rewrite-target annotation, which dynamically configures path rewrites using regular expressions.

The vulnerability, identified as CVE-2026-67309, exists within the auto-generated RewriteTarget middleware mechanism of Traefik. When handling rewrites, the proxy translates regular expression patterns into path replacement templates. Under specific pattern configurations, malicious HTTP requests can circumvent routing-layer authorization barriers while navigating to sensitive backend resources.

Classified under CWE-22, this path traversal flaw does not directly impact the local file system of the Traefik proxy. Instead, it alters the downstream request path forwarded to downstream services. This path modification results in an authentication bypass, as the proxy evaluates routing and security controls before executing the middleware-driven rewrite.

Root Cause Analysis

The root cause of CVE-2026-67309 resides in a technical discrepancy between Traefik's primary routing parser and the path modification performed by the RewriteTarget middleware. When an Ingress resource specifies an annotation like nginx.ingress.kubernetes.io/rewrite-target: /$1 alongside a loose regular expression like /api(.*), Traefik registers a routing rule matching the /api prefix.

When a malicious client sends a request to /api../admin, Traefik's routing phase analyzes the request path. At this point, the path /api../admin contains no valid dot-segment separators, meaning the directory traversal sequence .. is parsed as a literal part of the string api... Since this string starts with /api, the request matches the routing rule mapped to the public API controller.

Because the request matches the public API router, Traefik routes the traffic. Any authentication or authorization policies (such as BasicAuth, DigestAuth, or ForwardAuth) that protect the /admin path are ignored because the routing engine does not associate this request with the /admin route. The request successfully passes the routing layer without authorization.

Following the routing phase, Traefik passes the request to the RewriteTarget middleware. The regular expression ^/api(.*) is executed against /api../admin, capturing the group ../admin. The middleware substitutes this group into the target template, creating the rewritten path /../admin. Traefik forwards this unnormalized, traversable path directly to the downstream server, which cleans /../admin to /admin, exposing the restricted page.

Code-Level Vulnerability & Patch Analysis

To address this vulnerability, Traefik developers modified the request-handling logic in the RewriteTarget middleware, configuration snippet rewrite actions, and the ReplacePathRegex middleware. The primary fix introduces an invariant validation check after path modification, preventing unnormalized path segments from being forwarded downstream.

The fix leverages Go's standard library JoinPath() function to resolve any path-relative sequences before forwarding. The patched code verifies if the post-rewrite path remains equivalent to the sanitized path. If a difference is detected, indicating that directory traversal sequences were injected, the middleware terminates the request immediately with an HTTP 400 Bad Request status.

Below is the patched logic within pkg/middlewares/ingressnginx/rewritetarget/rewrite_target.go which enforces this constraint:

// Here we are sanitizing the URL when the path is not empty,
// as the JoinPath method is adding a leading slash if the path is empty.
path := req.URL.Path
if path != "" {
	req.URL = req.URL.JoinPath()
}
 
// Stop here if the normalization of the path produces a different path.
if path != req.URL.Path {
	logger.Debug().Msgf("Rejecting request, sanitized path: %q is not equivalent to stripped path: %q", path, req.URL.Path)
	http.Error(rw, http.StatusText(http.StatusBadRequest), http.StatusBadRequest)
	return
}

This check is consistently applied across multiple integration points. Similar modifications were introduced in pkg/middlewares/ingressnginx/snippet/action.go and pkg/middlewares/replacepathregex/replace_path_regex.go to ensure that any custom regex path replacement is subjected to the same structural validation. This comprehensive implementation blocks variants that attempt path replacement through alternative regex-driven configuration patterns.

Exploitation & Proof-of-Concept Analysis

Exploiting CVE-2026-67309 requires a specific combination of a loosely written regular expression in a Kubernetes Ingress resource and a downstream server that performs path normalization. An attacker does not require credentials, special network configurations, or user interaction. The attack is entirely unauthenticated and conducted over a standard HTTP connection.

An attacker begins by scanning public-facing Ingress definitions or sending speculative HTTP probes. If an Ingress maps /api(.*) to a rewrite target of /$1, the attacker constructs a payload targeting /api../<restricted_endpoint>. By omitting the slash after the initial segment, the routing parser is deceived into treating the payload as part of the public path.

Upon receiving the request, Traefik processes the rewrite, converting /api../admin into /../admin. The proxy forwards the raw rewritten URL to the target backend. The backend server receives /../admin, performs its own internal RFC-compliant URL parsing, collapses the dot-segments, and serves the resource mapped to /admin. The routing-layer authentication policies on Traefik are bypassed entirely, exposing the downstream administrative interface.

Re-exploitation, Bypass Potential, & Limitations

Evaluating the patch reveals potential edge cases where parser differentials between Traefik and downstream servers may persist. While the JoinPath() check successfully mitigates standard relative directory traversals on Unix-like targets, downstream environments running on Windows-based infrastructure may behave differently.

First, Go's standard library path cleaning on Unix targets does not evaluate the backslash (\) character as a folder separator. If an attacker submits a request targeting /api..\admin, the rewritten path resolves to /..\admin. Because Go's path cleaning does not collapse this sequence, the validation check passes. If the downstream application runs on Windows IIS or utilizes a framework that treats backslashes as forward slashes, it will normalize /..\admin to /admin, completing the bypass.

Second, double URL encoding remains an area of concern depending on backend parsing behavior. If an attacker submits /api%252e%252e/admin, Traefik decodes the first layer to /api%2e%2e/admin. The regex extracts %2e%2e/admin, which the JoinPath() validator evaluates as literal characters rather than dot-segments. If the downstream backend performs a second layer of URL decoding before executing path routing, it will translate %2e%2e/admin to ../admin and trigger the directory traversal.

Finally, matrix parameters or semicolon-delimited paths present potential bypass opportunities in Java environments. Servers like Apache Tomcat or Spring parse paths containing semicolons differently from standard Go routers. If Traefik fails to collapse sequences like /api/..;param/admin but the downstream server processes the semicolon to discard parameters and normalize the parent directory, unauthorized access may still be achieved.

Incident Detection & Mitigation Strategies

Remediation of CVE-2026-67309 requires upgrading Traefik to version v3.7.8 or higher. This release integrates the validation checks across all rewrite-related middleware components. Administrators should deploy the updated version using their standard Kubernetes lifecycle management tools, such as Helm or direct manifest updates.

If upgrading is not immediately possible, administrators must implement configuration workarounds. The primary configuration mitigation is to restrict regular expressions within Ingress resources to require explicit directory separators. Instead of using /api(.*), rewrite patterns must use /api/(.*). This forces any dot-segment input like /api/../admin to be normalized by Traefik prior to rule matching, correctly directing the request to the protected /admin route where authentication is enforced.

Additionally, security teams should implement Web Application Firewall (WAF) rules to inspect incoming requests. Detection signatures should target paths containing dot-segments directly adjacent to directory segments without a dividing slash. Monitoring logs for HTTP 400 Bad Request responses containing the debug log string 'Rejecting request, sanitized path' can assist in identifying active scanning or exploit attempts.

Official Patches

TraefikPrimary fix commit introducing JoinPath normalization validation check

Fix Analysis (3)

Technical Appendix

CVSS Score
7.8/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N
EPSS Probability
0.49%
Top 60% most exploited
15,000
via Shodan

Affected Systems

Traefik Proxy (Kubernetes Ingress NGINX provider environment with RewriteTarget enabled)

Affected Versions Detail

Product
Affected Versions
Fixed Version
Traefik
Traefik
>= v3.7.0, <= v3.7.7v3.7.8
AttributeDetail
CWE IDCWE-22
Attack VectorNetwork (AV:N)
CVSS v4.07.8 (High)
EPSS Score0.00492
Exploit StatusPoC (No Weaponized)
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located under a restricted parent directory, but the product does not properly neutralize special elements within the pathname.

Known Exploits & Detection

Wiz Vulnerability DatabaseExploit methodology and context details outlined in GHSA security advisory

Vulnerability Timeline

Development patches introduced internally.
2026-07-08
Initial testing and Gateway API test coverage fixes.
2026-07-09
Commits finalizing the JoinPath() sanitization checks.
2026-07-13
Vulnerability officially disclosed as CVE-2026-67309.
2026-08-01
NVD Record updated with primary CVSS scoring.
2026-08-03

References & Sources

  • [1]GitHub Security Advisory GHSA-8rxv-jg7p-wvg3
  • [2]VulnCheck Security Advisory

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•2 days ago•CVE-2026-53493
6.9

CVE-2026-53493: Uncontrolled Resource Consumption in containerd Image-Pull Descriptor Graph Resolution

containerd is an open-source container runtime. Prior to versions 1.7.36, 2.0.13, 2.2.9, 2.3.6, and 2.4.1, a crafted OCI index graph can force very high CPU/memory usage during PullImage (before container start), causing long ContainerCreating stalls and, at larger sizes, node/runtime instability. The vulnerability occurs because containerd's image-pull descriptor graph resolution handlers processed OCI image indices and manifests recursively without enforcing boundaries on traversal depth or breadth, and without maintaining a global visited registry to count duplicate references.

Alon Barad
Alon Barad
34 views•6 min read
•2 days ago•GHSA-62MM-XWMV-CRHG
7.5

GHSA-62MM-XWMV-CRHG: Unauthenticated Path Traversal in Khoj Static File Serving Endpoint

An unauthenticated path traversal vulnerability exists in the Khoj AI assistant platform via the static file serving endpoint `/home/{file_path:path}`. Due to improper path sanitization when handling user input with Python's pathlib module, a remote attacker can read arbitrary files from the server's filesystem.

Alon Barad
Alon Barad
13 views•5 min read
•2 days ago•CVE-2026-100369
8.4

CVE-2026-100369: Argument Injection Vulnerability in CliInvoke Process Runner Factories

An argument injection vulnerability (CWE-88) in CliInvoke and AlastairLundy.CliInvoke allows local attackers to execute arbitrary system commands. By injecting double-quote characters into target file paths or arguments, attackers can terminate operating-system-level quoted boundaries and introduce new commands when shell runners are utilized.

Amit Schendel
Amit Schendel
10 views•5 min read
•2 days ago•CVE-2026-100368
8.4

CVE-2026-100368: OS Command Injection in CliInvoke Shell Wrappers

An OS command injection vulnerability exists in the PowerShell and Cmd shell wrappers of the CliInvoke .NET library (specifically the CliInvoke.Specializations package). Under vulnerable configurations, arguments and targets are passed as a single flat string to ProcessStartInfo.Arguments, permitting double-quote breakout and execution of arbitrary secondary commands with host process privileges.

Amit Schendel
Amit Schendel
9 views•7 min read
•2 days ago•GHSA-VV77-66RF-PM86
8.8

GHSA-vv77-66rf-pm86: Gas Draining Vulnerability in mpp Multi-Party Payments Library

A critical-severity input validation vulnerability in the Elixir multi-party payment library `mpp` allows unauthenticated remote attackers to exhaust the transaction fee payer's wallet balance. By submitting a crafted Ethereum transaction envelope with artificially inflated gas parameters, an attacker can force the server to co-sign and commit to pay exorbitant fees, leading to severe financial loss and Denial of Service.

Amit Schendel
Amit Schendel
9 views•5 min read
•2 days ago•GHSA-QPXH-FF8M-C62V
7.5

GHSA-QPXH-FF8M-C62V: Gas Draining and Resource Exhaustion in ZenHive mpp Library

A critical gas draining vulnerability exists in the ZenHive mpp (Multi-Payment Protocol) library prior to version v0.6.0. By omitting validation of EIP-2930 access lists in custom 0x76 transaction envelopes, the library allows malicious clients to pad transaction payloads with dummy addresses, draining the gas sponsor's hot wallet.

Amit Schendel
Amit Schendel
8 views•8 min read