Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 3.7.3之前版本存在授权问题漏洞,该漏洞源于HTTP/3 (QUIC) TLS配置选择中对SNI值进行精确、区分大小写的查找,未能匹配通配符主机模式或主机名大小写变体,可能导致未经身份验证的客户端绕过路由器特定的mTLS强制策略。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-48491 | 7.8 HIGH | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypas |
| CVE-2026-48020 | 7.8 HIGH | Traefik StripPrefix Route-Level Auth Bypass via Path Normalization |
| CVE-2023-54365 | 7.5 HIGH | Traefik - Denial of Service via HTTP/2 Request Handling |
| CVE-2026-54762 | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails | |
| CVE-2026-54761 | Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the al |
No comments yet