# CVE-2026-71325

## Summary

- **CVE ID:** CVE-2026-71325
- **Severity:** MEDIUM
- **CVSS Score:** 4.8 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N)
- **CWE:** CWE-653, CWE-863
- **Published:** Aug 6, 2026
- **Last Modified:** Aug 7, 2026

## Description

Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.

## Affected Products

- traefik — traefik (< 2.11.54)
- traefik — traefik (>= 3.0.0, < 3.6.25)
- traefik — traefik (>= 3.7.0, < 3.7.10)

## References

- [CNA](https://github.com/traefik/traefik/security/advisories/GHSA-62fc-8686-hfmq)
- [CNA](https://github.com/traefik/traefik/commit/65ebf4b47fbdc33e3856803a5844a404e094d52d)
- [CNA](https://github.com/traefik/traefik/releases/tag/v2.11.54)
- [CNA](https://github.com/traefik/traefik/releases/tag/v3.6.25)
- [CNA](https://github.com/traefik/traefik/releases/tag/v3.7.10)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.13%
- **EPSS Percentile:** 3.1

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._