Aller au contenu
CodeAuditAgent

CVE-2026-85594

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Faiblesse

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Produits concernés

  • traefik traefik

Références

Trouvez la faille avant un attaquant.

Connectez-vous avec GitHub et lancez votre premier audit en moins d'une minute. L'offre gratuite ne nécessite aucune carte bancaire.