Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 2.10.5之前版本和3.0.0-beta4之前版本存在资源管理错误漏洞,该漏洞源于HTTP/2请求处理中存在拒绝服务漏洞,容易受到资源耗尽攻击,可能导致服务无响应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-53622 | 7.8 HIGH | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case ho |
| CVE-2026-48491 | 7.8 HIGH | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypas |
| CVE-2026-48020 | 7.8 HIGH | Traefik StripPrefix Route-Level Auth Bypass via Path Normalization |
| CVE-2026-54762 | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails | |
| CVE-2026-54761 | Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the al |
No comments yet