Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-85594

Опубликовано: 04 сент. 2026
Источник: redhat
CVSS3: 7.7

Описание

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

A flaw was found in Traefik. The software fails to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation within the Kubernetes Ingress provider. This vulnerability allows a namespace-limited tenant, even if excluded from the allowlist, to attach an operator-owned middleware to its Service. If this middleware injects backend credentials, the tenant can then recover these credentials at a controlled backend, leading to information disclosure.

Отчет

A flaw was found in Traefik's Kubernetes Ingress provider (v3.7.1 through v3.7.10) where crossProviderNamespaces isolation is not enforced for the service.middlewares Service annotation. In multi-tenant Kubernetes clusters, an authenticated namespace-restricted tenant excluded from cross-namespace allowlists can attach operator-owned middlewares from external namespaces to their Service. If the attached middleware injects upstream backend credentials, the unauthorized tenant can intercept and recover those credentials at a tenant-controlled backend endpoint.

Меры по смягчению последствий

Restrict user permissions to modify Service annotations using Kubernetes Admission Controllers or Kyverno policies to prevent unauthorized referencing of traefik.ingress.kubernetes.io/service.middlewares. Alternatively, disable cross-provider namespace resolution in the Traefik Ingress provider configuration until patched.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel8Not affected
Red Hat OpenShift GitOpsopenshift-gitops-1/argo-rollouts-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-1220
https://bugzilla.redhat.com/show_bug.cgi?id=2529861github.com/traefik/traefik: Traefik: Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider

7.7 High

CVSS3

Связанные уязвимости

nvd
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

debian
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces r ...

github
12 дней назад

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

7.7 High

CVSS3