Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 5

Количество 5

redhat логотип

CVE-2026-71325

около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 8.7
EPSS: Низкий
nvd логотип

CVE-2026-71325

около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 4.4
EPSS: Низкий
debian логотип

CVE-2026-71325

около 2 месяцев назад

Traefik is an open-source edge router that makes publishing services a ...

CVSS3: 4.4
EPSS: Низкий
github логотип

GHSA-62fc-8686-hfmq

около 2 месяцев назад

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

EPSS: Низкий
fstec логотип

BDU:2026-11279

около 2 месяцев назад

Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.2
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2026-71325

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 8.7
0%
Низкий
около 2 месяцев назад
nvd логотип
CVE-2026-71325

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
debian логотип
CVE-2026-71325

Traefik is an open-source edge router that makes publishing services a ...

CVSS3: 4.4
0%
Низкий
около 2 месяцев назад
github логотип
GHSA-62fc-8686-hfmq

Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

0%
Низкий
около 2 месяцев назад
fstec логотип
BDU:2026-11279

Уязвимость функции nameAndService() файла pkg/provider/kubernetes/crd/kubernetes_http.go провайдера интеграции с Kubernetes CRD обратного прокси сервера Containous Traefik, позволяющая нарущителю получить несанкционированный доступ к защищаемой информации

CVSS3: 5.2
0%
Низкий
около 2 месяцев назад

Уязвимостей на страницу