v3.6.21
greensock/GSAPv3.6.21Jun 10, 2026by github-actions[bot]
AI Summary
A follow-up patch addressing specific CVEs and bug fixes related to Kubernetes Gateway API, TLS configuration, and proxy protocol versions.
Key Highlights
- Fixed CVE-2026-54761 security vulnerability.
- Enforced rejection of cross-provider backendRefs.namespace.
- Bumped github.com/pires/go-proxyproto to v0.12.0.
- Fixed TLS routers with same host but different tlsoptions on different entryPoints.
Full Release Notes
**CVE fixed:** - [CVE-2026-54761](https://nvd.nist.gov/vuln/detail/CVE-2026-54761) (Advisory [GHSA-3g6v-2r68-prfc](https://github.com/traefik/traefik/security/advisories/GHSA-3g6v-2r68-prfc)) **Bug fixes:** - **[k8s/gatewayapi]** Reject cross-provider references with backendRefs.namespace ([#13322](https://github.com/traefik/traefik/pull/13322) @youkoulayley) - **[server]** Bump to github.com/pires/go-proxyproto v0.12.0 ([#13313](https://github.com/traefik/traefik/pull/13313) @timschumi) - **[tls]** Fix routers with same host, different tlsoptions on different entryPoint ([#13329](https://github.com/traefik/traefik/pull/13329) @juliens) - **[tls]** Fix snicheck for routers with no hosts ([#13333](https://github.com/traefik/traefik/pull/13333) @rtribotte)