Executive brief
Traefik is an ingress controller and reverse proxy used to route traffic to Kubernetes services. A namespace isolation feature intended to prevent cross-tenant resource access fails to validate service middleware annotations, allowing a restricted tenant to attach operator-controlled middleware that can leak backend credentials. An attacker with Kubernetes namespace privileges can recover sensitive API keys or tokens that the middleware injects.
Technical details
The vulnerability is an authorization bypass in the Kubernetes Ingress provider where the crossProviderNamespaces allowlist is not enforced for the traefik.ingress.kubernetes.io/service.middlewares Service annotation. The vulnerable code in pkg/provider/kubernetes/ingress/kubernetes.go::loadService copies service middleware references without validating the Service's namespace membership. A low-privilege Kubernetes tenant restricted to an excluded namespace can annotate its own Service with a middleware reference from another provider (e.g., operator-secret@file), and Traefik will execute that middleware on requests to the tenant's backend. If the middleware injects credentials like API keys or bearer tokens, the attacker can recover those credentials by sending requests from a controlled backend. The fix is available in v3.7.11.
Affected products
- Traefik Traefik v3.7.1 to v3.7.10
Timeline
- 2026-08-21: disclosed: GHSA-m6wx-622r-48r9 published
- 2026-09-04: other: CVE-2026-85594 and VulnCheck advisory published
- 2026-09-11: patched: Traefik v3.7.11 released (estimated based on typical patch timing)