cbcvebase.

Traefik vulnerabilities

72 known vulnerabilities affecting traefik/traefik.

Total CVEs
72
CISA KEV
1
actively exploited
Public exploits
2
Exploited in wild
1
Severity breakdown
CRITICAL13HIGH36MEDIUM20LOW3

Vulnerabilities

Page 2 of 4
CVE-2026-65602P3HIGHCVSS 8.8≥ 3.6.0, < 3.6.23≥ 3.7.0, < 3.7.72026-07-22
CVE-2026-65602 [HIGH] CWE-863 CVE-2026-65602: Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces all Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@fi
nvd
CVE-2026-88009P3HIGHCVSS 8.8fixed in 2.11.57v>= 3.0.0, < 3.7.132026-09-10
CVE-2026-88009 [HIGH] CWE-444 CVE-2026-88009: Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefi Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against a path normalized to /
nvd
CVE-2026-54765P3HIGHCVSS 8.5≥ 3.7.0, < 3.7.6v>= 3.7.0, < 3.7.62026-07-06
CVE-2026-54765 [HIGH] CWE-284 CVE-2026-54765: Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that bac
nvd
CVE-2019-12452P3HIGHCVSS 7.5≥ 1.7.0, ≤ 1.7.112019-05-29
CVE-2019-12452 [HIGH] CWE-522 CVE-2019-12452: types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API i types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficient access control (which is contrary to the API documentation), allows remote authenticated users to discover password hashes by reading the Basic HTTP Authentication or Digest HTTP Authentication section
nvd
CVE-2026-85596P3HIGHCVSS 8.2≥ 3.7.0, ≤ 3.7.102026-09-04
CVE-2026-85596 [HIGH] CWE-287 CVE-2026-85596: Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingress namespace and name. As a result, two Ingress objects sharing the same host, the same client CA secre
nvd
CVE-2026-32695P3HIGHCVSS 7.7fixed in 3.6.11v3.7.0-ea1+1 more2026-03-27
CVE-2026-32695 [HIGH] CWE-74 CVE-2026-32695: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative `rules[].hosts[]` was exploitable for host restriction bypass (for example `ten
nvd
CVE-2026-29054P3HIGHCVSS 7.5≥ 2.11.9, < 2.11.38≥ 3.1.3, < 3.6.9+2 more2026-03-05
CVE-2026-29054 [HIGH] CWE-178 CVE-2026-29054: Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X-Forwarded headers. When Traefik processes HTTP/1.1 requests, the protection put in place to prevent the removal of Traefik-managed X-Forwarded headers (su
nvd
CVE-2018-15598P3HIGHCVSS 7.5≥ 1.6.0, < 1.6.62018-08-21
CVE-2018-15598 [HIGH] CWE-287 CVE-2018-15598: Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if a Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
nvd
CVE-2026-88007P3CRITICALCVSS 9.1v>= 2.11.0, < 2.11.57v>= 3.0.0, < 3.7.132026-09-10
CVE-2026-88007 [CRITICAL] CWE-287 CVE-2026-88007: Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13 Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bo
nvd
CVE-2024-45410P3HIGHCVSS 7.5fixed in 2.11.9≥ 3.0.0, < 3.1.3+1 more2024-09-19
CVE-2024-45410 [HIGH] CWE-345 CVE-2024-45410: Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, ce Traefik is a golang, Cloud Native Application Proxy. When a HTTP request is processed by Traefik, certain HTTP headers such as X-Forwarded-Host or X-Forwarded-Port are added by Traefik before the request is routed to the application. For a HTTP client, it should not be possible to remove or modify these headers. Since the application trusts the value
nvd
CVE-2026-25949P3HIGHCVSS 7.5fixed in 3.6.82026-02-12
CVE-2026-25949 [HIGH] CWE-400 CVE-2026-25949: Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerabili Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinit
nvd
CVE-2026-71327P3HIGHCVSS 7.6v>= 3.0.0, < 3.6.25v>= 3.7.0, < 3.7.102026-08-06
CVE-2026-71327 [HIGH] CWE-694 CVE-2026-71327: Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute, GRPCRoute, TCPRoute, and TLSRoute router and service identities by hyphen-concatenating namespace, rou
nvd
CVE-2026-26999P3HIGHCVSS 7.5fixed in 2.11.38≥ 3.0.0, < 3.6.9+1 more2026-03-05
CVE-2026-26999 [HIGH] CWE-400 CVE-2026-26999: Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline used to bound protocol sniffing is cleared before the TLS handshake is completed. When a TLS handshake re
nvd
CVE-2023-39325P3HIGHCVSS 7.5fixed in 2.10.5≥ 3.0.0-beta1, < 3.0.0-beta42023-10-11
CVE-2023-39325 [HIGH] CWE-770 CVE-2023-39325: A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause exces A malicious HTTP/2 client which rapidly creates requests and immediately resets them can cause excessive server resource consumption. While the total number of requests is bounded by the http2.Server.MaxConcurrentStreams setting, resetting an in-progress request allows the attacker to create a new request while the existing one is still executing. Wit
nvd
CVE-2022-23632P3HIGHCVSS 7.5fixed in 2.6.12022-02-17
CVE-2022-23632 [HIGH] CWE-295 CVE-2022-23632: Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router Traefik is an HTTP reverse proxy and load balancer. Prior to version 2.6.1, Traefik skips the router transport layer security (TLS) configuration when the host header is a fully qualified domain name (FQDN). For a request, the TLS configuration choice can be different than the router choice, which implies the use of a wrong TLS configuration. When sen
nvd
CVE-2026-71324P3HIGHCVSS 7.0fixed in 2.11.53v>= 3.0.0, < 3.6.24+1 more2026-08-06
CVE-2026-71324 [HIGH] CWE-444 CVE-2026-71324: Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http.Transport. When the upstream answers the CONNECT with a keep-alive non-2xx response and does not drain
nvd
CVE-2024-28869P3HIGHCVSS 7.5fixed in 2.11.2v3.0.0+1 more2024-04-12
CVE-2024-28869 [HIGH] CWE-755 CVE-2024-28869: Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to an Traefik is an HTTP reverse proxy and load balancer. In affected versions sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default configuration. This vulnerability can be exploited by attackers to induce a denial of service. This vulnerability has been addressed in version 2.
nvd
CVE-2023-54365P3HIGHCVSS 7.5fixed in 2.10.5v3.0.0-beta1+2 more2026-06-23
CVE-2023-54365 [HIGH] CVE-2023-54365: Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 req Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailabil
nvd
CVE-2024-39321P3HIGHCVSS 7.5fixed in 2.11.6≥ 3.0.0, < 3.0.4+3 more2024-07-05
CVE-2024-39321 [HIGH] CWE-639 CVE-2024-39321: Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 h Traefik is an HTTP reverse proxy and load balancer. Versions prior to 2.11.6, 3.0.4, and 3.1.0-rc3 have a vulnerability that allows bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes sent with spoofed IP addresses. Versions 2.11.6, 3.0.4, and 3.1.0-rc3 contain a patch for this issue. No known workarounds are available.
nvd
CVE-2026-22045P3HIGHCVSS 7.5fixed in 2.11.35≥ 3.0.0, < 3.6.7+1 more2026-01-15
CVE-2026-22045 [HIGH] CWE-770 CVE-2026-22045: Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can o
nvd
Traefik vulnerabilities | cvebase