Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71325

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.7

Описание

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

A flaw was found in Traefik. This flaw allows a tenant, even when restricted by Role-Based Access Control (RBAC) to a single namespace, to bypass namespace isolation. By binding their own router to a TraefikService in another namespace, an attacker can expose or reroute that namespace's backend services. This defeats the intended allowCrossNamespace=false enforcement, leading to unauthorized access or manipulation of services across namespaces.

Отчет

A flaw in Traefik's service resolver allows a lower-privileged tenant to reference and bind cross-namespace TraefikService objects via @kubernetescrd, even when allowCrossNamespace=false is configured. By creating a custom router targeting an isolated TraefikService CRD in a separate namespace, an authenticated attacker can bypass namespace isolation controls, intercepting or rerouting backend service traffic across multi-tenant boundaries.

Меры по смягчению последствий

To mitigate this flaw, restrict RBAC permissions to prevent non-administrative users from creating or modifying custom Traefik IngressRoute and TraefikService Custom Resource Definitions (CRDs). Alternatively, segregate sensitive backend workloads into dedicated Traefik ingress controller instances.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-653
https://bugzilla.redhat.com/show_bug.cgi?id=2512238github.com/traefik/traefik: Traefik: Namespace isolation bypass via TraefikService backendRef

8.7 High

CVSS3

Связанные уязвимости

CVSS3: 4.4
nvd
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 4.4
debian
около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a ...

github
около 2 месяцев назад

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

CVSS3: 5.2
fstec
около 2 месяцев назад

Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации

8.7 High

CVSS3