Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

traefik — Vulnerabilities & Security Advisories 67

All 67 CVE vulnerabilities found in traefik, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities associated with Traefik, a popular open-source reverse proxy and load balancer, focusing on common weakness types such as deserialization flaws, privilege escalation, and input validation errors. It collects disclosed security issues reported against the product, covering the period from its initial release through the most recent advisories published. Readers can use this resource to track the vendor's security posture, analyze the evolution of specific vulnerability classes within the Traefik ecosystem, and review the product's full vulnerability history without needing to search individual bulletins. The collection is curated from public security advisories and bug tracker entries, providing a consolidated view of known defects and their resolutions. This aggregation helps developers and security teams identify recurring patterns, assess remediation timelines, and prioritize patching efforts based on severity and impact. By centralizing this information, the page supports informed decision-making regarding upgrade paths and security monitoring strategies for deployments running Traefik.

Vendor: traefik

CVE ID Title CVSS Severity Published
CVE-2026-88010 Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle CWE-208 6.3 Medium 2026-09-22
CVE-2026-88012 Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded CWE-770 5.3 Medium 2026-09-10
CVE-2026-88011 Traefik: ForwardAuth identity spoofing via dot-form header alias CWE-290 5.3 Medium 2026-09-10
CVE-2026-88009 Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging CWE-444 8.8 High 2026-09-10
CVE-2026-88008 Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization CWE-444 7.0 High 2026-09-10
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse CWE-287 9.1 Critical 2026-09-10
CVE-2026-88004 Traefik entrypoint header-name sanitization bypassed via request trailers CWE-436 7.0 High 2026-09-10
CVE-2026-88879 Traefik before v2.11.56 Identity Spoofing via Header Alias CWE-290 5.3 Medium 2026-09-10
CVE-2026-88878 Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass CWE-770 5.3 Medium 2026-09-10
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect CWE-639 9.8 Critical 2026-09-10
CVE-2026-85597 Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict CWE-863 8.2 High 2026-09-04
CVE-2026-85596 Traefik v3.7 Authentication Bypass via TLS Option Conflict CWE-287 8.2 High 2026-09-04
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth CWE-287 9.3 Critical 2026-09-04
CVE-2026-85594 Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware CWE-639 7.0 High 2026-09-04
CVE-2026-71327 Traefik: Gateway API route identity collision allows cross-namespace backend hijacking CWE-694 7.6 High 2026-08-06
CVE-2026-71326 Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing CWE-287 2.1 Low 2026-08-06
CVE-2026-71325 Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef CWE-653 4.8 Medium 2026-08-06
CVE-2026-71324 Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool CWE-444 7.0 High 2026-08-06
CVE-2026-67309 Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass CWE-22 7.8 High 2026-08-01
CVE-2026-65602 Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass CWE-863 5.3 Medium 2026-07-22
CVE-2026-65600 Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex CWE-22 7.8 High 2026-07-22
CVE-2026-65601 Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef CWE-863 5.3 Medium 2026-07-22
CVE-2026-54763 Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth CWE-178 - - 2026-07-06
CVE-2026-54765 Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port CWE-284 - - 2026-07-06
CVE-2026-54764 ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false CWE-345 - - 2026-07-06
CVE-2026-54762 Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails CWE-636 - - 2026-06-23
CVE-2026-54761 Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services CWE-284 - - 2026-06-23
CVE-2026-53622 Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts CWE-288 7.8 High 2026-06-23
CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass CWE-288 7.8 High 2026-06-23
CVE-2026-48020 Traefik StripPrefix Route-Level Auth Bypass via Path Normalization CWE-288 7.8 High 2026-06-23

All 67 known CVE vulnerabilities affecting traefik with full Chinese analysis, references, and POCs where available.