Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 3.6.21之前版本和3.7.0版本至3.7.5之前版本存在安全漏洞,该漏洞源于Kubernetes Gateway提供者中授权访问控制问题,可能导致在命名空间未允许列表中的HTTPRoute通过引用网关API ReferenceGrant覆盖的允许列表命名空间,暴露内部Traefik服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-53622 | 7.8 HIGH | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case ho |
| CVE-2026-48491 | 7.8 HIGH | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypas |
| CVE-2026-48020 | 7.8 HIGH | Traefik StripPrefix Route-Level Auth Bypass via Path Normalization |
| CVE-2023-54365 | 7.5 HIGH | Traefik - Denial of Service via HTTP/2 Request Handling |
| CVE-2026-54762 | Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails |
No comments yet