traefik
Networking Infrastructureoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting traefik.
- CVE-2026-65602Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass8.8
- CVE-2026-65601Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef8.8
- CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex5.3
- CVE-2026-54763Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth10.0
- CVE-2026-54765Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port8.5
- CVE-2026-54764ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false5.8
- CVE-2026-54762Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails8.6
- CVE-2026-54761Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services7.1
- CVE-2026-53622Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts10.0
- CVE-2026-48491Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass10.0
- CVE-2026-48020Traefik StripPrefix Route-Level Auth Bypass via Path Normalization10.0
- CVE-2023-54365Traefik - Denial of Service via HTTP/2 Request Handling7.5
- CVE-2026-44774Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false9.9
- CVE-2026-41181Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service5.8
- CVE-2026-41263Traefik: BasicAuth middleware: timing side-channel vulnerability3.7