cbcvebase.

Github.Com Traefik Traefik V2 vulnerabilities

57 known vulnerabilities affecting github.com/traefik_traefik_v2.

Total CVEs
57
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH24MEDIUM25LOW1

Vulnerabilities

Page 3 of 3
CVE-2026-54764P3MEDIUM≥ 0, < 2.11.512026-08-06
CVE-2026-54764 [MEDIUM] CWE-345 Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false ## Summary There is a medium severity vulnerability in Traefik's ForwardAuth middleware. Even when configured with `trustForwardHeader: false`, Traefik derives the `X-Forwarded-Port` header sent to the authenticati
ghsa
CVE-2022-23469P3LOW≥ 0, < 2.9.62022-12-08
CVE-2022-23469 [LOW] CWE-200 Traefik may display authorization header in the debug logs Traefik may display authorization header in the debug logs ### Impact There is a potential vulnerability in Traefik displaying the Authorization header in its debug logs. Traefik uses [oxy](https://github.com/vulcand/oxy) to provide the following features: - Round Robin: https://doc.traefik.io/traefik/routing/services/#weighted-round-robin-service - Buffering: https://doc.traefik.io/traefik/middlewares/ht
ghsaosv
CVE-2022-46153P3MEDIUM≥ 0, < 2.9.62022-12-08
CVE-2022-46153 [MEDIUM] CWE-295 Traefik routes exposed with an empty TLSOption Traefik routes exposed with an empty TLSOption ## Impact There is a potential vulnerability in Traefik managing the TLS connections. A router configured with a not well-formatted [TLSOption](https://doc.traefik.io/traefik/v2.9/https/tls/#tls-options) is exposed with an empty TLSOption. For instance, a route secured using an mTLS connection set with a wrong CA file is exposed without verifying the client certificat
ghsaosv
CVE-2026-41174P3MEDIUM≥ 0, < 2.11.432026-04-24
CVE-2026-41174 [MEDIUM] CWE-653 Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding ## Summary There is a vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When `providers.kubernetesCRD.allowCrossNamespace=false`, Traefik correctly rejects direct cross-namespace middleware references from `IngressRoute` objects, but fails to apply the same restriction
ghsa
CVE-2026-32305P4HIGH≥ 0, < 2.11.412026-03-20
CVE-2026-32305 [HIGH] CWE-287 Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config ## Summary There is a potential vulnerability in Traefik's TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across multiple records, Traefik's SNI extr
ghsaosv
CVE-2026-41181P4MEDIUM≥ 0, < 2.11.442026-05-04
CVE-2026-41181 [MEDIUM] CWE-201 Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service ## Summary There is a medium severity information disclosure vulnerability in Traefik's `errors` (custom error pages) middleware. When the backend returns a response matching the configured status range, the middleware forwards the original request's complete head
ghsa
CVE-2026-88011P4MEDIUM≥ 0, < 2.11.562026-09-10
CVE-2026-88011 [MEDIUM] CWE-290 Traefik: ForwardAuth identity spoofing via dot-form header alias Traefik: ForwardAuth identity spoofing via dot-form header alias ## Summary There is a medium severity vulnerability in Traefik's handling of request headers whose name aliases another header name. Go canonicalizes header names on dashes only, so `X-Auth-User`, `X_Auth_User` and `X.Auth.User` are three distinct headers to Traefik, while backends that derive variable names from header names (CGI, WS
ghsa
CVE-2024-53259P4MEDIUMCVSS 6.5≥ 0, < 2.11.152024-12-17
CVE-2024-53259 [MEDIUM] Traefik affected by CVE-2024-53259 Traefik affected by CVE-2024-53259 There is a potential vulnerability in Traefik managing HTTP/3 connections. More details in the [CVE-2024-53259](https://nvd.nist.gov/vuln/detail/CVE-2024-53259). ## Patches - https://github.com/traefik/traefik/releases/tag/v2.11.15 - https://github.com/traefik/traefik/releases/tag/v3.2.2 ## Workarounds No workaround ## For more information If you have any questions or comments about this advisor
ghsaosv
CVE-2023-47124P4MEDIUM≥ 0, < 2.10.62023-12-05
CVE-2023-47124 [MEDIUM] CWE-400 Traefik vulnerable to potential DDoS via ACME HTTPChallenge Traefik vulnerable to potential DDoS via ACME HTTPChallenge ## Impact There is a potential vulnerability in Traefik managing the ACME HTTP challenge. When Traefik is configured to use the [HTTPChallenge](https://doc.traefik.io/traefik/https/acme/#httpchallenge) to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attacker
ghsaosv
CVE-2024-24788P4MEDIUMCVSS 5.9≥ 0, < 2.11.32024-05-23
CVE-2024-24788 [MEDIUM] CWE-1395 Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop ### Impact There is a vulnerability in [GO managing malformed DNS message](https://groups.google.com/g/golang-announce/c/wkkO4P9stm0), which impacts Traefik. This vulnerability could be exploited to cause a denial of service. ### References - [CVE-2024-24788](https://www.cve.org/CVERecord?id=
ghsaosv
CVE-2024-35255P4MEDIUMCVSS 5.5≥ 0, < 2.11.52024-06-20
CVE-2024-35255 [MEDIUM] CWE-362 ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability ### Impact There is a vulnerability in [Azure Identity Libraries and Microsoft Authentication Library Elevation of Privilege Vulnerability](https://nvd.nist.gov/vuln/detail/CVE-2024-35255). ### References - [CVE-2024-35255](https://nvd.nist.gov/vuln/detail/CVE-2024-35255) ### Patches - https://github.com/traefik/trae
ghsaosv
CVE-2024-52003P4MEDIUM≥ 0, < 2.11.142024-12-02
CVE-2024-52003 [MEDIUM] CWE-601 Traefik's X-Forwarded-Prefix Header still allows for Open Redirect Traefik's X-Forwarded-Prefix Header still allows for Open Redirect ### Impact There is a vulnerability in Traefik that allows the client to provide the `X-Forwarded-Prefix` header from an untrusted source. ### Patches - https://github.com/traefik/traefik/releases/tag/v2.11.14 - https://github.com/traefik/traefik/releases/tag/v3.2.1 ### Workarounds No workaround. ### For more information If
ghsaosv
CVE-2026-88012P4MEDIUM≥ 2.8.2, < 2.11.562026-09-10
CVE-2026-88012 [MEDIUM] CWE-770 Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded ## Summary There is a medium severity vulnerability in Traefik's HTTP/3 entry points: the `respondingTimeouts` settings were not applied to the HTTP/3 request path. `readTimeout` in particular is on by default at 60s and is documented as bounding the time to rea
ghsa
CVE-2026-26998P4MEDIUM≥ 0, < 2.11.382026-03-04
CVE-2026-26998 [MEDIUM] CWE-770 Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS ## Impact There is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no `maxResponseBodySize`
ghsaosv
CVE-2026-71325P4MEDIUM≥ 0, < 2.11.542026-08-06
CVE-2026-71325 [MEDIUM] CWE-653 Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef ## Summary There is a medium severity vulnerability in Traefik's Kubernetes CRD provider. When `providers.kubernetesCRD.allowCrossNamespace` is disabled — the default — cross-namespace `@kubernetescrd` references are rejected for middlewares, TLS options and HTTP/TCP ServersTransport
ghsa
CVE-2026-41263P4MEDIUMCVSS 6.3≥ 0, < 2.11.432026-04-24
CVE-2026-41263 [MEDIUM] CWE-208 Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware ## Summary There is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences. The variable intended to hold a constant-time fallback secret always re
ghsa
CVE-2026-32595P4MEDIUM≥ 0, < 2.11.412026-03-20
CVE-2026-32595 [MEDIUM] CWE-208 Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration ## Summary There is a potential vulnerability in Traefik's BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt password comparison taking ~166ms. When the username does not exist, the response returns immediat
ghsaosv
Github.Com Traefik Traefik V2 vulnerabilities | cvebase