Research / Finding
Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values F-TRAEFIK-006
Public snapshot: 26 Sep 2026. Status, releases and attribution belong to each source below; none is inferred from another record.
Read the evidence · View in research browse
Recorded evidence
8.7high
Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values
Fixed in: v3.6.10
patched
details
Finding IDs F-TRAEFIK-006 CVE CVE-2026-29777 GHSA GHSA-8q2w-wr49-whqj Status patched Fixed in v3.6.10 CVSS vector CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N CVE registry state PUBLISHED CVE state checked 23 Sep 2026 Upstream title Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values Upstream CWE CWE-74 Upstream publication 11 Mar 2026 Upstream updated 11 Mar 2026 Metadata fetched 23 Sep 2026 Upstream @1seal credit @1seal: reporter (accepted) F-TRAEFIK-006: Code / markup injection. Backticks in rule data change rule-expression interpretation. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TRAEFIK-006
Security area (1seal assessment): Semantics. Backticks in rule data change rule-expression interpretation. Reviewed 24 Sep 2026.
Clarify or correct this record privately . The email subject includes the finding ID. For an existing case, continue the agreed private thread. Do not post unpublished vulnerability details in public issues. Research disclosure policy .
How this page groups evidence This identifier groups recorded evidence; it is not an additional CVE, independent-vulnerability count or guarantee of vendor confirmation. Fixed code, released versions, attribution and independent discovery are distinct claims. Absent metadata means not recorded, not disproved. Counting rules .