traefik
Networking Infrastructureoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting traefik.
- CVE-2026-88010Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
- CVE-2026-88012Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded5.3
- CVE-2026-88011Traefik: ForwardAuth identity spoofing via dot-form header alias8.1
- CVE-2026-88009Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging8.2
- CVE-2026-88008Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization9.1
- CVE-2026-88007Traefik HTTP/3 Backend NTLM Connection Reuse9.1
- CVE-2026-88004Traefik entrypoint header-name sanitization bypassed via request trailers7.4
- CVE-2026-88879Traefik before v2.11.56 Identity Spoofing via Header Alias8.2
- CVE-2026-88878Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass5.3
- CVE-2026-88877Traefik v3.7.0 Authentication Bypass via from-to-www-redirect9.8
- CVE-2026-85596Traefik v3.7 Authentication Bypass via TLS Option Conflict9.8
- CVE-2026-85597Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict9.1
- CVE-2026-85595Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth9.8
- CVE-2026-85594Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware9.8
- CVE-2026-71327Traefik: Gateway API route identity collision allows cross-namespace backend hijacking8.1