CVE-2026-44774
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false in github.com/traefik/traefik
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/traefik/traefik/security/advisories/GHSA-96qj-4jj5-wcjc, https://nvd.nist.gov/vuln/detail/CVE-2026-44774, https://github.com/traefik/traefik/releases/tag/v2.11.46, https://github.com/traefik/traefik/releases/tag/v3.6.17, https://github.com/traefik/traefik/releases/tag/v3.7.1