Traefik是Traefik公司开源的一款负载均衡器。 Traefik 2.11.54之前版本、3.0.0至3.6.25之前版本和3.7.0至3.7.10之前版本存在安全漏洞,该漏洞源于服务解析器处理TraefikService后端引用时未拒绝跨命名空间的@kubernetescrd引用,可能导致被RBAC限定在单个命名空间内的租户将自身路由器绑定到其他命名空间拥有的TraefikService,暴露或重路由该命名空间的后端,从而破坏allowCrossNamespace=false所强制的命名空间隔离
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-71327 | 7.6 HIGH | Traefik: Gateway API route identity collision allows cross-namespace backend hijacking |
| CVE-2026-71324 | 7.0 HIGH | Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend kee |
| CVE-2026-71326 | 2.1 LOW | Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing |
No comments yet