Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-71325

Опубликовано: 06 авг. 2026
Источник: debian
EPSS Низкий

Описание

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
traefikitppackage

EPSS

Процентиль: 4%
0.00139
Низкий

Связанные уязвимости

CVSS3: 8.7
redhat
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 4.4
nvd
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

github
около 2 месяцев назад

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

CVSS3: 5.2
fstec
около 2 месяцев назад

Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 4%
0.00139
Низкий