Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-54761

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik evaluates the allowlist against the target backendRef.namespace instead of the route's own namespace. As a result, an HTTPRoute created in a namespace that is not allow-listed can reference a cross-provider TraefikService such as api@internal, dashboard@internal or rest@internal by pointing backendRef.namespace at an allow-listed namespace covered by a Gateway API ReferenceGrant, exposing internal Traefik services on the data plane. Exploitation requires the ability to create an accepted HTTPRoute and a matching ReferenceGrant from an allow-listed namespace; it does not require any change to Traefik static configuration, RBAC, or the deployment itself. This vulnerability is fixed in 3.6.21 and 3.7.5.

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This vulnerability exists in the Kubernetes Gateway provider's crossProviderNamespaces allowlist. A remote attacker with the ability to create an accepted HTTPRoute and a matching ReferenceGrant can exploit this by misconfiguring the backendRef.namespace to bypass the allowlist. This allows the attacker to expose internal Traefik services, such as the API or dashboard, on the data plane, leading to information disclosure.

Отчет

Red Hat OpenShift Dev Spaces ships a version of traefik affected by this vulnerability. The flaw allows a user with Kubernetes RBAC permissions to create HTTPRoute resources to bypass the crossProviderNamespaces allowlist and access internal Traefik services such as api@internal. No upstream fix is available for the shipped v2 line; fixes exist only in v3.6.21+ and v3.7.5+. Exploitation requires specific Kubernetes Gateway API configuration with crossProviderNamespaces and existing ReferenceGrant permissions.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-863
https://bugzilla.redhat.com/show_bug.cgi?id=2491920traefik: Traefik: Internal service exposure due to crossProviderNamespaces allowlist misconfiguration

EPSS

Процентиль: 24%
0.00318
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik evaluates the allowlist against the target backendRef.namespace instead of the route's own namespace. As a result, an HTTPRoute created in a namespace that is not allow-listed can reference a cross-provider TraefikService such as api@internal, dashboard@internal or rest@internal by pointing backendRef.namespace at an allow-listed namespace covered by a Gateway API ReferenceGrant, exposing internal Traefik services on the data plane. Exploitation requires the ability to create an accepted HTTPRoute and a matching ReferenceGrant from an allow-listed namespace; it does not require any change to Traefik static configuration, RBAC, or the deployment itself. This vulnerability is fixed in 3.6.21 and 3.7.5.

CVSS3: 7.1
debian
около 1 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 an ...

CVSS3: 7.1
github
около 2 месяцев назад

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

EPSS

Процентиль: 24%
0.00318
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-54761