Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

traefik — Vulnerabilities & Security Advisories 66

Browse all 66 CVE security advisories affecting traefik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Traefik functions as an open-source edge router and reverse proxy, primarily designed to simplify the deployment of microservices by automatically discovering and configuring backend services. Its architecture focuses on dynamic configuration, allowing it to integrate seamlessly with container orchestration platforms like Docker and Kubernetes. Historically, the software has been susceptible to several critical vulnerability classes, including remote code execution, path traversal, and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls within its HTTP middleware and entry point configurations. With thirty-three recorded CVEs, recent incidents have highlighted risks related to unauthorized access to the dashboard and potential denial-of-service conditions. While the project maintains an active security response process, the high volume of disclosed flaws underscores the complexity of managing dynamic routing logic in distributed environments, requiring diligent patching and strict configuration hygiene to mitigate exposure.

Found 66 results / 66 Clear Filters
Top products by traefik: traefik
CVE ID Title CVSS Severity Published
CVE-2026-88010 Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle — traefik CWE-208 6.3 Medium 2026-09-22
CVE-2026-88012 Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded — traefik CWE-770 5.3 Medium 2026-09-10
CVE-2026-88011 Traefik: ForwardAuth identity spoofing via dot-form header alias — traefik CWE-290 5.3 Medium 2026-09-10
CVE-2026-88009 Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging — traefik CWE-444 8.8 High 2026-09-10
CVE-2026-88008 Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization — traefik CWE-444 7.0 High 2026-09-10
CVE-2026-88007 Traefik HTTP/3 Backend NTLM Connection Reuse — traefik CWE-287 9.1 Critical 2026-09-10
CVE-2026-88004 Traefik entrypoint header-name sanitization bypassed via request trailers — traefik CWE-436 7.0 High 2026-09-10
CVE-2026-88879 Traefik before v2.11.56 Identity Spoofing via Header Alias — traefik CWE-290 5.3 Medium 2026-09-10
CVE-2026-88878 Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass — traefik CWE-770 5.3 Medium 2026-09-10
CVE-2026-88877 Traefik v3.7.0 Authentication Bypass via from-to-www-redirect — traefik CWE-639 9.8 Critical 2026-09-10
CVE-2026-85597 Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict — traefik CWE-863 8.2 High 2026-09-04
CVE-2026-85596 Traefik v3.7 Authentication Bypass via TLS Option Conflict — traefik CWE-287 8.2 High 2026-09-04
CVE-2026-85595 Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth — traefik CWE-287 9.3 Critical 2026-09-04
CVE-2026-85594 Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware — traefik CWE-639 7.0 High 2026-09-04
CVE-2026-71327 Traefik: Gateway API route identity collision allows cross-namespace backend hijacking — traefik CWE-694 7.6 High 2026-08-06
CVE-2026-71326 Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing — traefik CWE-287 2.1 Low 2026-08-06
CVE-2026-71325 Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef — traefik CWE-653 4.8 Medium 2026-08-06
CVE-2026-71324 Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool — traefik CWE-444 7.0 High 2026-08-06
CVE-2026-67309 Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass — traefik CWE-22 7.8 High 2026-08-01
CVE-2026-65602 Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass — traefik CWE-863 5.3 Medium 2026-07-22
CVE-2026-65600 Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex — traefik CWE-22 7.8 High 2026-07-22
CVE-2026-65601 Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef — traefik CWE-863 5.3 Medium 2026-07-22
CVE-2026-54763 Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth — traefik CWE-178 - - 2026-07-06
CVE-2026-54765 Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port — traefik CWE-284 - - 2026-07-06
CVE-2026-54764 ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false — traefik CWE-345 - - 2026-07-06
CVE-2026-54762 Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails — traefik CWE-636 - - 2026-06-23
CVE-2026-54761 Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services — traefik CWE-284 - - 2026-06-23
CVE-2026-53622 Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts — traefik CWE-288 7.8 High 2026-06-23
CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass — traefik CWE-288 7.8 High 2026-06-23
CVE-2026-48020 Traefik StripPrefix Route-Level Auth Bypass via Path Normalization — traefik CWE-288 7.8 High 2026-06-23

This page lists every published CVE security advisory associated with traefik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.