CVE-2026-54761
HighAdvisory
Published 17 Jun 2026In the index since 6 Sept 2026
- Severity
- High
- worst across findings
- CVSS
- 7.1
- base score, highest
- EPSS
- 0.004
- 30th percentile
- CISA KEV
- Not listed
- no confirmed exploitation
- Charts affected
- 13
- of 17,781 indexed, latest versions
- Container images
- 12
- deployed by those charts
- Fix available
- 1 of 2
- affected packages
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Carried by container images the latest versions of 13 of 17,781 indexed charts deploy, on 12 images.
| Affected package | Affected versions | Fixed in | Images |
|---|---|---|---|
| github.com/ | v0.0.0-20230427144611-7805c683e333, v0.0.0-20231128144610-dae0491b612a, v0.0.0-20240212151404-0c8778639a3c, v2.8.3+3 more | no fix listed | 8 |
| github.com/ | v0.0.0-20250331083804-bd4ff8181890, v3.0.0-beta4, v3.6.12, v3.6.13+1 more | 3.6.21, 3.7.5 | 5 |
- OSV records
- GHSA-3g6v-2r68-prfc
- Also known as
- GO-2026-5083
Charts affected
13 by stars
| Chart | Latest | Affected images | Radar Score |
|---|---|---|---|
| syftopenmined | 0.9.5 | 1 of 6See more | 17,245 |
| daskhubdask | 2024.1.1 | 1 of 9See more | 14,094 |
| forecastlestakaterVerified publisher | 2.1.1 | 1 of 1See more | 712 |
| traefik-meshtraefikOfficialVerified publisher | 4.1.1 | 1 of 7See more | 9,257 |
| cosmo-controller-managercosmoVerified publisher | 0.9.0 | 1 of 2See more | 1,927 |
| cosmo-dashboardcosmoVerified publisher | 0.9.1 | 1 of 1See more | 1,939 |
| switchboardswitchboardVerified publisher | 0.7.4 | 1 of 1See more | 839 |
| traefik-hubtraefikOfficialVerified publisher | 4.2.0 | 1 of 1See more | 3,165 |
| caninecanine | 0.1.10 | 1 of 7See more | 14,130 |
| traefikcanine | 40.2.0 | 1 of 1See more | 1,023 |
| cosmo-traefikcosmoVerified publisher | 0.9.1 | 1 of 2See more | 3,672 |
| dask-gatewaydask | 2026.3.0 | 1 of 2See more | 1,994 |
| traefikgpg-dev | 39.0.8 | 1 of 1See more | 1,274 |
Container images carrying it
12 by charts deploying them
A fixed version is listed for 1 of the 2 affected packages.
| Container image | Digest | Package | Fixed in | Used by |
|---|---|---|---|---|
| library/ | 6b9cbca6fac4 | github.com/ | 3.7.5 | 2 |
| library/ | 0a5157f742d2 | github.com/ | no fix listed | 1 |
| library/ | 104204dadedf | github.com/ | 3.6.21 | 1 |
| library/ | 1489caffaedb | github.com/ | no fix listed | 1 |
| library/ | 1957e3314f43 | github.com/ | no fix listed | 1 |
| library/ | 34d5089d0b41 | github.com/ | 3.6.21 | 1 |
| stakater/ | 382cd9572352 | github.com/ | no fix listed | 1 |
| traefik/ | cf071f3e165c | github.com/ | no fix listed | 1 |
| ghcr.io/ | 54a193b757da | github.com/ | 3.6.21 | 1 |
| ghcr.io/ | 8c7fa5552028 | github.com/ | no fix listed | 1 |
| ghcr.io/ | 6a1c4a81a924 | github.com/ | no fix listed | 1 |
| ghcr.io/ | 322f5f8cc105 | github.com/ github.com/ | no fix listed 3.6.21 | 1 |