Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-71327

Опубликовано: 06 авг. 2026
Источник: redhat
CVSS3: 8.5

Описание

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.

A flaw was found in Traefik, an open-source HTTP reverse proxy and load balancer. Its Kubernetes Gateway API provider incorrectly generates unique identifiers for routes and services. This vulnerability allows an attacker to create conflicting routes, which can then overwrite the backend services of another isolated environment (namespace). This could lead to unauthorized control over services in different namespaces.

Отчет

A flaw in Traefik's Kubernetes Gateway API provider allows a lower-privileged tenant to overwrite backend routing rules across namespace boundaries. Due to deterministic route identity generation concatenating namespace, route name, Gateway identity, entry point, and rule index using hyphens, identical generated string identifiers result in name collisions. An authenticated attacker can exploit these predictable identifiers to deploy conflicting HTTPRoute, GRPCRoute, TCPRoute, or TLSRoute objects, effectively hijacking, rerouting, or disrupting backend service traffic intended for isolated namespaces.

Меры по смягчению последствий

To mitigate this flaw, restrict RBAC permissions to prevent untrusted tenants from creating or modifying Kubernetes Gateway API route resources (HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute). Alternatively, deploy isolated Traefik ingress controller instances with single-namespace scope enforcement.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2512294github.com/traefik/traefik: Traefik: Cross-namespace backend hijacking due to Gateway API identity collision

8.5 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
nvd
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, route name, Gateway identity, entry point, and rule index, allowing colliding Routes to overwrite another namespace's backend. This issue is fixed in 3.6.25 and 3.7.10.

CVSS3: 8.1
debian
около 2 месяцев назад

Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...

CVSS3: 8.2
github
около 2 месяцев назад

Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

CVSS3: 6.8
fstec
около 2 месяцев назад

Уязвимость файлов pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go и tlsroute.go провайдера Kubernetes Gateway API обратного прокси сервера Containous Traefik, позволяющая нарущителю оказать воздействие на конфиденциальность и целостность защищаемой информации

8.5 High

CVSS3