Traefik v3.7.1 及更高版本在 Kubernetes Ingress 提供者中未能对 服务注解(即 )强制执行 限制。一个被排除在允许列表之外的命名空间受限租户,可以将其所属的服务关联到由运维人员(operator)拥有的中间件;若该中间件用于注入后端凭据,攻击者便可以在其控制的后端中获取这些凭据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85595 | 9.3 CRITICAL | Traefik before v2.11.55 Authentication Bypass via digestAuth |
| CVE-2026-85596 | 8.2 HIGH | Traefik v3.7 Authentication Bypass via TLS Option Conflict |
| CVE-2026-85597 | 8.2 HIGH | Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict |
No comments yet