CVE-2026-85594

    Dashboard / Vulnerabilities / CVE-2026-85594

    CVE-2026-85594

    Published: 4 Sept 2026Last Modified: 18 Sept 2026

    Summary: Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware

    Details: Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist can attach an operator-owned middleware to its Service, and if that middleware injects backend credentials, recover them at a controlled backend.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- fa49e2bcad7ffd8a80accdf1fae1ae480913d93d

    Affected versions

    v3.7.10
    v3.7.9
    v3.7.8
    v3.7.7
    v3.7.6
    v3.7.5
    v3.7.4
    v3.7.3
    v3.7.2
    v3.7.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-85594 | CVE-DB