Vulnerabilities in traefik

66 results
Vexday analysis

Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.

CVE-2026-67309HIGHTraefik v3.7.0 Path Traversal via RewriteTarget Authentication BypassEPSS 0.7%CVE-2026-88877CRITICALTraefik v3.7.0 Authentication Bypass via from-to-www-redirectEPSS 0.6%CVE-2026-53622HIGHTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hostsEPSS 0.6%CVE-2023-47106MEDIUMIncorrect processing of fragment in the URL leads to Authorization Bypass in TraefikEPSS 0.6%CVE-2026-65600HIGHTraefik before v2.11.52 Authentication Bypass via ReplacePathRegexEPSS 0.6%CVE-2026-29054HIGHTraefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)EPSS 0.6%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.6%CVE-2026-88007CRITICALTraefik HTTP/3 Backend NTLM Connection ReuseEPSS 0.6%CVE-2024-39321HIGHTraefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakesEPSS 0.6%CVE-2026-33433MEDIUMTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldEPSS 0.6%CVE-2026-26998MEDIUMTraefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS)EPSS 0.6%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%CVE-2026-32695MEDIUMTraefik has Knative Ingress Rule Injection that Allows Host Restriction BypassEPSS 0.5%CVE-2026-88012MEDIUMTraefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unboundedEPSS 0.5%CVE-2026-65601MEDIUMTraefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRefEPSS 0.5%CVE-2022-46153HIGHRoutes exposed with an empty TLSOption in traefikEPSS 0.5%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.5%CVE-2026-88008HIGHTraefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect AuthorizationEPSS 0.5%CVE-2026-71327HIGHTraefik: Gateway API route identity collision allows cross-namespace backend hijackingEPSS 0.5%CVE-2026-85594HIGHTraefik v3.7.1 crossProviderNamespaces Bypass via Service MiddlewareEPSS 0.5%