VYPR
Medium severity4.4GHSA Advisory· Published Aug 6, 2026· Updated Sep 16, 2026

CVE-2026-71325

CVE-2026-71325

Description

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
github.com/traefik/traefik/v2Go
< 2.11.542.11.54
github.com/traefik/traefik/v3Go
>= 3.0.0, < 3.6.253.6.25
github.com/traefik/traefik/v3Go
>= 3.7.0, < 3.7.103.7.10
github.com/traefik/traefikGo
<= 1.7.34

Affected products

3

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.