Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-71325

Опубликовано: 06 авг. 2026
Источник: nvd
CVSS3: 4.4
EPSS Низкий

Описание

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия до 2.11.54 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.6.25 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.7.0 (включая) до 3.7.10 (включая)

EPSS

Процентиль: 4%
0.00139
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-653

Связанные уязвимости

CVSS3: 8.7
redhat
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 4.4
debian
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a ...

github
около 2 месяцев назад

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

CVSS3: 5.2
fstec
около 2 месяцев назад

Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 4%
0.00139
Низкий

4.4 Medium

CVSS3

Дефекты

CWE-653