Junglewise Threat Intelligence

CVE-2026-41174: GO-2026-5760 - Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding in github.com/traefik/traefik

CVE-2026-41174 · Severity: low · CVSS 3.1 · Published 2026-06-25

Technologies: github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Go.

Executive brief

Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding in github.com/traefik/traefik

Affected products

  • Go github.com/traefik/traefik/v3
  • Go github.com/traefik/traefik/v2
  • Go github.com/traefik/traefik

Related threats