A vulnerability has been found in Traefik up to 3.7.6 and classified as problematic. The impacted element is an unknown function of the file HTTPRoute.spec.rules of the component Kubernetes Gateway API Provider. The manipulation of the argument rules/backendRefs/filters leads to injection.

This vulnerability is documented as CVE-2026-65601. The attack can be initiated remotely. There is not any exploit available.