REDHAT-BUG-2452235: High severity Traefik traefik vulnerability
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative rules[].hosts[] was exploitable for host restriction bypass (for example tenant.example.com) || Host(attacker.com), producing a router that serves attacker-controlled hosts. Knative headers[].exact also allows rule-syntax injection and proves unsafe rule construction. In multi-tenant clusters, this can route unauthorized traffic to victim services and lead to cross-tenant traffic exposure. Versions 3.6.11 and 3.7.0-ea.2 patch the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Traefik (Knative provider)to a version that resolves this vulnerability.Fixed in 3.6.11 - Upgrade
Upgrade
Traefik (Knative provider)to a version that resolves this vulnerability.Fixed in 3.7.0-ea.2
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2452235?
The severity of REDHAT-BUG-2452235 is high, rated at 7.
How do I fix REDHAT-BUG-2452235?
To fix REDHAT-BUG-2452235, upgrade to Traefik version 3.6.11 or later, or 3.7.0-ea.2 or later.
What components are affected by REDHAT-BUG-2452235?
REDHAT-BUG-2452235 affects the Traefik HTTP reverse proxy and load balancer, specifically its Knative provider.
What is the impact of REDHAT-BUG-2452235?
The impact of REDHAT-BUG-2452235 includes potential exposure to security vulnerabilities due to user-controlled values in router rule expressions.
When was REDHAT-BUG-2452235 published?
REDHAT-BUG-2452235 was published on March 27, 2026.