CVE-2026-71325
Received Received - Intake

Cross-Namespace TraefikService Access Bypass

Vulnerability report for CVE-2026-71325, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: GitHub, Inc.

Description

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-07
AI Q&A
2026-08-07
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
traefik traefik to 2.11.54 (inc)
traefik traefik to 3.6.25 (inc)
traefik traefik to 3.7.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-863 The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.
CWE-653 The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Traefik versions before 2.11.54, 3.6.25, and 3.7.10 allow cross-namespace references for TraefikService backends. This means a user restricted to one namespace via RBAC can bind their router to a TraefikService in another namespace, bypassing the intended namespace isolation enforced by allowCrossNamespace=false.

Impact Analysis

An attacker with limited access to a single namespace could exploit this to expose or reroute services in other namespaces, potentially gaining unauthorized access to sensitive data or disrupting services.

Compliance Impact

This vulnerability could lead to unauthorized data exposure or service disruption, violating principles of data isolation and access control required by GDPR and HIPAA.

Mitigation Strategies

Upgrade Traefik to version 2.11.54, 3.6.25, or 3.7.10 or later to address the cross-namespace reference issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71325. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart