Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware
Published Sep 4, 2026
7.0
HIGHCVSS 4.0
EPSS 0.48%
Description
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.
Affected products
-
- Version 3.7.1StatusaffectedConstraints<=3.7.12
- Version
No data.
Red Hat OpenShift Dev Spaces
devspaces/traefik-rhel9
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel8
Not affected
Red Hat OpenShift GitOps
openshift-gitops-1/argo-rollouts-rhel9
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Dev Spaces | devspaces/traefik-rhel9 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel8 | Not affected | n/a |
| Red Hat OpenShift GitOps | openshift-gitops-1/argo-rollouts-rhel9 | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
A flaw was found in Traefik's Kubernetes Ingress provider (v3.7.1 through v3.7.10) where crossProviderNamespaces isolation is not enforced for the service.middlewares Service annotation. In multi-tenant Kubernetes clusters, an authenticated namespace-restricted tenant excluded from cross-namespace allowlists can attach operator-owned middlewares from external namespaces to their Service. If the attached middleware injects upstream backend credentials, the unauthorized tenant can intercept and recover those credentials at a tenant-controlled backend endpoint.
Red Hat mitigation
Restrict user permissions to modify Service annotations using Kubernetes Admission Controllers or Kyverno policies to prevent unauthorized referencing of traefik.ingress.kubernetes.io/service.middlewares. Alternatively, disable cross-provider namespace resolution in the Traefik Ingress provider configuration until patched.
References (7)
- https://access.redhat.com/security/cve/CVE-2026-85594 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2529861 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71017 Advisory
- https://github.com/traefik/traefik/security/advisories/GHSA-m6wx-622r-48r9 vendor-advisoryExploitPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-85594
- https://www.cve.org/CVERecord?id=CVE-2026-85594
- https://www.vulncheck.com/advisories/traefik-3.7.1-crossprovidernamespaces-bypass-via-service-middleware third-party-advisoryThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-85594 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2529861 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-71017 | Advisory | |
| https://github.com/traefik/traefik/security/advisories/GHSA-m6wx-622r-48r9 | vendor-advisoryExploitPatchVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-85594 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-85594 | ||
| https://www.vulncheck.com/advisories/traefik-3.7.1-crossprovidernamespaces-bypass-via-service-middleware | third-party-advisoryThird Party Advisory |
Change history (0)
No recorded changes yet.