Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-85594— Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

Quick assessment

Affected
traefik traefik
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Traefik v3.7.1 及更高版本在 Kubernetes Ingress 提供者中未能对 服务注解(即 )强制执行 限制。一个被排除在允许列表之外的命名空间受限租户,可以将其所属的服务关联到由运维人员(operator)拥有的中间件;若该中间件用于注入后端凭据,攻击者便可以在其控制的后端中获取这些凭据。

CVSS 7.0 · High

Affected Version Matrix 1

VendorProduct Version RangeStatus
traefik traefik 3.7.1≤ 3.7.12 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-85594

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware
Source: CVE Program / CVE List V5
Vulnerability Description
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
通过用户控制密钥绕过授权机制
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
traefik traefik 3.7.1 ~ 3.7.12 -

II. Public POCs for CVE-2026-85594

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-85594

登录查看更多情报信息。

Vendor Advisories for CVE-2026-85594 (2)

Same Patch Batch · traefik · 2026-09-04 · 4 CVEs total

CVE-2026-85595 9.3 CRITICAL Traefik before v2.11.55 Authentication Bypass via digestAuth
CVE-2026-85596 8.2 HIGH Traefik v3.7 Authentication Bypass via TLS Option Conflict
CVE-2026-85597 8.2 HIGH Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict

IV. Related Vulnerabilities

V. Comments for CVE-2026-85594

No comments yet


Leave a comment