CVE-2026-71325
CVE Details
Visit the official vulnerability details page for CVE-2026-71325 to learn more.
Initial Publication
08/06/2026
Last Update
08/06/2026
Third Party Dependency
github.com/traefik/traefik/v3
NIST CVE Summary
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Received
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.2.1 | ⚠️ Impacted | ⚠️ Impacted |
| 1.1.8 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.