Impact
Traefik v3.7.1 fails to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A tenant with namespace-level privileges can attach an operator-owned middleware to a Service through that annotation. If the middleware injects backend credentials, the tenant can recover those credentials from a controlled backend, effectively bypassing intended namespace boundaries and accessing secrets that the tenant should not be able to obtain.
Affected Systems
The vulnerability affects Traefik deployments running the Kubernetes Ingress provider that use the traefik.ingress.kubernetes.io/service.middlewares annotation. The flaw is present in the v3.7.1 release; information on whether later releases have addressed the issue is not provided. Any environment using v3.7.1 or earlier that has not applied the CVE‑fix is susceptible.
Risk and Exploitability
The CVSS score of 7.0 indicates moderate severity, while the EPSS score of < 1% shows probability of exploitation is low. Exploitation requires the attacker or a tenant to modify a Service and attach a middleware that injects backend credentials. If such middleware exists, the risk escalates; otherwise the vector is constrained. Organizations should treat this as a moderate risk that warrants timely patching or mitigation.
OpenCVE Enrichment