Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

traefik — Vulnerabilities & Security Advisories 66

Browse all 66 CVE security advisories affecting traefik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Traefik functions as an open-source edge router and reverse proxy, primarily designed to simplify the deployment of microservices by automatically discovering and configuring backend services. Its architecture focuses on dynamic configuration, allowing it to integrate seamlessly with container orchestration platforms like Docker and Kubernetes. Historically, the software has been susceptible to several critical vulnerability classes, including remote code execution, path traversal, and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls within its HTTP middleware and entry point configurations. With thirty-three recorded CVEs, recent incidents have highlighted risks related to unauthorized access to the dashboard and potential denial-of-service conditions. While the project maintains an active security response process, the high volume of disclosed flaws underscores the complexity of managing dynamic routing logic in distributed environments, requiring diligent patching and strict configuration hygiene to mitigate exposure.

Found 66 results / 66 Clear Filters
Top products by traefik: traefik
CVE ID Title CVSS Severity Published
CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling — Traefik CWE-400 7.5 High 2026-06-23
CVE-2026-44774 Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false — traefik CWE-284 6.4 Medium 2026-05-15
CVE-2026-41181 Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service — traefik CWE-201 - - 2026-05-15
CVE-2026-41263 Traefik: BasicAuth middleware: timing side-channel vulnerability — traefik CWE-208 3.7 - 2026-04-30
CVE-2026-40912 Traefik: StripPrefixRegex auth bypass via Path/RawPath desync — traefik CWE-706 8.2 - 2026-04-30
CVE-2026-39858 Traefik: Forwarded alias spoofing top pre-auth decision bypass — traefik CWE-290 9.8 - 2026-04-30
CVE-2026-35051 Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth — traefik CWE-345 9.1 - 2026-04-30
CVE-2026-41174 Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding — traefik CWE-863 9.3 - 2026-04-30
CVE-2026-33433 Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField — traefik CWE-290 8.1 - 2026-03-27
CVE-2026-32695 Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass — traefik CWE-74 10.0 - 2026-03-27
CVE-2026-32595 Traefik: BasicAuth Middleware Timing Attack Allows Username Enumeration — traefik CWE-208 3.7 - 2026-03-20
CVE-2026-32305 Traefik mTLS bypass via fragmented ClientHello SNI extraction failure — traefik CWE-287 7.5 - 2026-03-20
CVE-2026-29777 Traefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values — traefik CWE-74 5.4AI Medium AI 2026-03-11
CVE-2026-29054 Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`) — traefik CWE-178 7.5 High 2026-03-05
CVE-2026-26999 Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS) — traefik CWE-400 7.5 High 2026-03-05
CVE-2026-26998 Traefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS) — traefik CWE-770 4.4 Medium 2026-03-05
CVE-2026-25949 Traefik: TCP readTimeout bypass via STARTTLS on Postgres — traefik CWE-400 7.5 High 2026-02-12
CVE-2026-22045 Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall — traefik CWE-770 5.9 Medium 2026-01-15
CVE-2025-66491 Traefik has Inverted TLS Verification Logic in its ingress-nginx Provider — traefik CWE-295 5.9 Medium 2025-12-09
CVE-2025-66490 Traefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules — traefik CWE-436 9.8AI Critical AI 2025-12-09
CVE-2025-54386 Traefik's Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution — traefik CWE-22 9.8 - 2025-08-01
CVE-2025-47952 Traefik allows path traversal using url encoding — traefik CWE-22 9.1AI Critical AI 2025-05-30
CVE-2025-32431 Traefik has a possible vulnerability with the path matchers — traefik CWE-22 5.9 - 2025-04-21
CVE-2024-52003 X-Forwarded-Prefix Header still allows for Open Redirect in traefik — traefik CWE-601 5.3 - 2024-11-29
CVE-2024-45410 HTTP client can remove the X-Forwarded headers in Traefik — traefik CWE-345 9.8 Critical 2024-09-19
CVE-2024-39321 Traefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes — traefik CWE-639 7.5 High 2024-07-05
CVE-2024-28869 Possible denial of service vulnerability with Content-length header in Traefik — traefik CWE-755 7.5 High 2024-04-12
CVE-2023-47633 Uncontrolled Resource Consumption in Traefik — traefik CWE-400 7.5 High 2023-12-04
CVE-2023-47106 Incorrect processing of fragment in the URL leads to Authorization Bypass in Traefik — traefik CWE-20 4.8 Medium 2023-12-04
CVE-2023-47124 Denial of service whith ACME HTTPChallenge in Traefik — traefik CWE-772 5.9 Medium 2023-12-04

This page lists every published CVE security advisory associated with traefik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.