CVE-2026-71325

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-08-06 22:18

Updated : 2026-09-08 20:53


NVD link : CVE-2026-71325

Mitre link : CVE-2026-71325

CVE.ORG link : CVE-2026-71325


JSON object : View

Products Affected

No product.

CWE
CWE-653

Improper Isolation or Compartmentalization

CWE-863

Incorrect Authorization