cbcvebase.

Traefik vulnerabilities

72 known vulnerabilities affecting traefik/traefik.

Total CVEs
72
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH36MEDIUM20LOW3

Vulnerabilities

Page 1 of 4
CVE-2023-44487P1HIGHCVSS 7.5KEVPoCfixed in 2.10.5v3.0.0-beta1+2 more2023-10-10
CVE-2023-44487 [HIGH] CWE-400 CVE-2023-44487: The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancell The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
nvd
CVE-2026-48020P2CRITICALCVSS 10.0fixed in 2.11.48≥ 3.0.0, < 3.6.19+3 more2026-06-23
CVE-2026-48020 [CRITICAL] CWE-288 CVE-2026-48020: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router matches on a PathPrefix rule and applies the StripPrefix middleware,
nvd
CVE-2026-53622P2CRITICALCVSS 10.0fixed in 3.7.3v>= 3.7.0, < 3.7.3+2 more2026-06-23
CVE-2026-53622 [CRITICAL] CWE-288 CVE-2026-53622: Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 hav Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake selects the applicable TLS c
ghsanvd
CVE-2026-39858P2CRITICALCVSS 10.0fixed in 2.11.43≥ 3.0.0, < 3.6.14+6 more2026-04-30
CVE-2026-39858 [CRITICAL] CWE-290 CVE-2026-39858: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc. Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canonical header names (e.g., X-Forwarded-Proto) and doe
nvd
CVE-2026-85595P2CRITICALCVSS 9.3fixed in 2.11.55≥ 3.0.0, ≤ 3.7.102026-09-04
CVE-2026-85595 [CRITICAL] CWE-287 CVE-2026-85595: Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypas Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid digest response using the empty secret and arbitrary credentials to bypass authentication on any digestA
nvd
CVE-2026-35051P2CRITICALCVSS 10.0fixed in 2.11.43≥ 3.0.0, < 3.6.14+6 more2026-04-30
CVE-2026-35051 [CRITICAL] CWE-345 CVE-2026-35051: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc. Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and
nvd
CVE-2026-44774P2CRITICALCVSS 9.9fixed in 2.11.46≥ 3.0.0, < 3.6.17+3 more2026-05-15
CVE-2026-44774 [CRITICAL] CWE-284 CVE-2026-44774: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's K Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gateway provider accepts any TraefikService backend reference whose name
nvd
CVE-2026-48491P2CRITICALCVSS 10.0≥ 3.7.0, < 3.7.3v>= 3.7.0, < 3.7.32026-06-23
CVE-2026-48491 [CRITICAL] CWE-288 CVE-2026-48491: Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a router uses a wildcard host rule such as Host(*.example.com) with strict
ghsanvd
CVE-2026-54763P2CRITICALCVSS 10.0fixed in 2.11.51≥ 3.0.0, < 3.6.22+3 more2026-07-06
CVE-2026-54763 [CRITICAL] CWE-178 CVE-2026-54763: Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik' Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms
nvd
CVE-2026-33433P3HIGHCVSS 8.8fixed in 2.11.42≥ 3.0.0, < 3.6.12+4 more2026-03-27
CVE-2026-33433 [HIGH] CWE-290 CVE-2026-33433: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea. Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The bac
nvd
CVE-2025-54386P3CRITICALCVSS 9.8fixed in 2.11.7≥ 3.0.0, < 3.4.4+3 more2025-08-02
CVE-2025-54386 [CRITICAL] CWE-22 CVE-2025-54386: Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4 Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the
nvd
CVE-2025-47952P3CRITICALCVSS 9.1fixed in 2.11.25≥ 3.0.0, < 3.4.1+1 more2025-05-30
CVE-2025-47952 [CRITICAL] CWE-22 CVE-2025-47952: Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 a Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if the URL contains a URL en
nvd
CVE-2026-40912P3HIGHCVSS 8.2fixed in 2.11.43≥ 3.0.0, < 3.6.14+6 more2026-04-30
CVE-2026-40912 [HIGH] CWE-706 CVE-2026-40912: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc. Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The middleware matches the regex against the decoded URL path but uses the resu
nvd
CVE-2026-88877P3CRITICALCVSS 9.8≥ 3.7.0, ≤ 3.7.132026-09-10
CVE-2026-88877 [CRITICAL] CWE-639 CVE-2026-88877: Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kuberne Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect annotation. For such Ingresses the provider creates an additional 'sibling' router that matches on
nvd
CVE-2025-32431P3CRITICALCVSS 9.1fixed in 2.11.24≥ 3.0.0, < 3.3.6+3 more2025-04-21
CVE-2025-32431 [CRITICAL] CWE-22 CVE-2025-32431: Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.2 Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. In versions prior to 2.11.24, 3.3.6, and 3.4.0-rc2. There is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if the URL co
nvd
CVE-2020-15129P3MEDIUMCVSS 4.7PoCfixed in 1.7.26≥ 2.2.0, < 2.2.8+1 more2020-07-30
CVE-2020-15129 [MEDIUM] CWE-601 CVE-2020-15129: In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vuln In Traefik before versions 1.7.26, 2.2.8, and 2.3.0-rc3, there exists a potential open redirect vulnerability in Traefik's handling of the "X-Forwarded-Prefix" header. The Traefik API dashboard component doesn't validate that the value of the header "X-Forwarded-Prefix" is a site relative path and will redirect to any header provided URI. Successful
nvd
CVE-2026-54762P3HIGHCVSS 8.6≥ 3.7.0, < 3.7.5v>= 3.7.0-ea.1, < 3.7.52026-06-23
CVE-2026-54762 [HIGH] CWE-636 CVE-2026-54762: Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium s Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through the supported nginx.ingress.kubernetes.io/auth-type and auth-secret annotat
nvd
CVE-2026-85597P3HIGHCVSS 8.2fixed in 2.11.55≥ 3.0.0, ≤ 3.7.102026-09-04
CVE-2026-85597 [HIGH] CWE-863 CVE-2026-85597: Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerab Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a
nvd
CVE-2026-67309P3HIGHCVSS 7.8≥ 3.7.0, < 3.7.82026-08-01
CVE-2026-67309 [HIGH] CWE-22 CVE-2026-67309: Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes In Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses a regex that captures attacker-controlled text without requiring a path separator (e.g., path /api(.*) w
nvd
CVE-2026-65601P3HIGHCVSS 8.8≥ 3.7.0, < 3.7.72026-07-22
CVE-2026-65601 [HIGH] CWE-863 CVE-2026-65601: Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes G Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of the HTTPRoute namespace. A low-privileged route author holding a ReferenceGrant for a cross-namespace
ghsanvd
Traefik vulnerabilities | cvebase