Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 traefik 3.7.0-ea.1版本至3.7.5之前版本存在安全漏洞,该漏洞源于Kubernetes Ingress NGINX provider中身份验证中间件未正确安装,导致受影响的路由认证失败,可能允许未经身份验证的攻击者访问后端服务。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2023-54365 | 7.5 HIGH | Traefik - Denial of Service via HTTP/2 Request Handling |
| CVE-2026-53622 | Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case ho | |
| CVE-2026-48491 | Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypas | |
| CVE-2026-48020 | Traefik StripPrefix Route-Level Auth Bypass via Path Normalization | |
| CVE-2026-54761 | Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the al |
No comments yet