CVE-2026-71325: Traefik
Medium severity, CVSS 4.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
Affected products
- Traefik Traefik: before 2.11.54 (fixed in 2.11.54); from 3.0.0, before 3.6.25 (fixed in 3.6.25); from 3.7.0, up to and including 3.7.10
Published 2026-08-06. Last modified 2026-09-16.