CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-71325

mediumcovered by 2 sourcesfirst seen 2026-08-06
Summary There is a medium severity vulnerability in Traefik's Kubernetes CRD provider. When providers.kubernetesCRD.allowCrossNamespace is disabled — the default — cross-namespace @kubernetescrd references are rejected for middlewares, TLS options and HTTP/TCP ServersTransports, but the same restriction was not applied to TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. Traefik v2 releases and the unmaintained v3 minor lines below v3.6 are affected and will not receive a patch on their own line; the remedy for those users is upgrading to a maintained, patched release. Patches - https://github.com/traefik/traefik/releases/tag/v2.11.54 - https://github.com/traefik/traefik/releases/tag/v3.6.25 - https://github.com/traefik/traefik/releases/tag/v3.7.10 For more information If you have any questions or comments about this advisory, please open an issue. <details> <summary>Original Description</summary> Summary When providers.kubernetesCRD.allowCrossNamespace=false (the default), Traefik correctly rejects cross-namespace @kubernetescrd references for middlewares, TLS options, and HTTP/TCP ServersTransport, but it does not apply the same restriction to service (TraefikService) backendRefs. As a result, a Kubernetes tenant who is confined by RBAC to their own namespace can bind their own router to a TraefikService owned by another namespace simply by referencing it as <victim-namespace>-<name>@kubernetescrd, defeating the namespace-isolation boundary that allowCrossNamespace=false is meant to enforce. This is the service-resolver sibling of the cross-namespace isolation family that Traefik has been fixing one resolver at a time (df00d82f / CVE-2026-41174 for Chain middlewares, and 67501cbe for T

⚡ Watch CVE-2026-71325

Get an email if CVE-2026-71325 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-71325

CVE.org record

Embed the live status

CVE-2026-71325 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-71325 status](https://www.csirts.com/badge/CVE-2026-71325)](https://www.csirts.com/cve/CVE-2026-71325)