Back

HIGH

Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

Published Sep 4, 2026

Description

Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

Affected products

Remediation

Red Hat statement

A flaw was found in Traefik's Kubernetes Ingress provider (v3.7.1 through v3.7.10) where crossProviderNamespaces isolation is not enforced for the service.middlewares Service annotation. In multi-tenant Kubernetes clusters, an authenticated namespace-restricted tenant excluded from cross-namespace allowlists can attach operator-owned middlewares from external namespaces to their Service. If the attached middleware injects upstream backend credentials, the unauthorized tenant can intercept and recover those credentials at a tenant-controlled backend endpoint.

Red Hat mitigation

Restrict user permissions to modify Service annotations using Kubernetes Admission Controllers or Kyverno policies to prevent unauthorized referencing of traefik.ingress.kubernetes.io/service.middlewares. Alternatively, disable cross-provider namespace resolution in the Traefik Ingress provider configuration until patched.

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 8, 2026
Reserved Sep 4, 2026
CISA Vulnrichment
Updated Sep 8, 2026
NVD
Status Analyzed
Modified Sep 16, 2026
Red Hat
Severity Important
Public date Sep 4, 2026
ENISA EUVD
Assigner VulnCheck
Published Sep 4, 2026
Updated Sep 8, 2026
Exploited since n/a
EUVD-2026-71017