Vulnerabilities in traefik
66 resultsVexday analysis
Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.
CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.5%CVE-2026-88004HIGHTraefik entrypoint header-name sanitization bypassed via request trailersEPSS 0.5%CVE-2026-88009HIGHTraefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access loggingEPSS 0.4%CVE-2026-85596HIGHTraefik v3.7 Authentication Bypass via TLS Option ConflictEPSS 0.4%CVE-2026-54762MEDIUMTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsEPSS 0.4%CVE-2026-88878MEDIUMTraefik v2.8.2 through v3.6 HTTP/3 Timeout BypassEPSS 0.4%CVE-2026-88011MEDIUMTraefik: ForwardAuth identity spoofing via dot-form header aliasEPSS 0.4%CVE-2026-41263MEDIUMTraefik: BasicAuth middleware: timing side-channel vulnerabilityEPSS 0.4%CVE-2024-52003MEDIUMX-Forwarded-Prefix Header still allows for Open Redirect in traefikEPSS 0.4%CVE-2026-32595MEDIUMTraefik: BasicAuth Middleware Timing Attack Allows Username EnumerationEPSS 0.4%CVE-2026-29777MEDIUMTraefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesEPSS 0.4%CVE-2026-54761MEDIUMTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesEPSS 0.4%CVE-2025-66490MEDIUMTraefik doesn't Prevent Path Normalization Bypass in Router + Middleware RulesEPSS 0.4%CVE-2026-48491HIGHTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypassEPSS 0.4%CVE-2026-85597HIGHTraefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option ConflictEPSS 0.4%CVE-2026-22045MEDIUMTraefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallEPSS 0.3%CVE-2026-54765MEDIUMTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portEPSS 0.3%CVE-2026-71326LOWTraefik: BasicAuth singleflight key collision allows authenticated identity spoofingEPSS 0.3%CVE-2026-65602MEDIUMTraefik before 3.6.23 IngressRouteTCP ServersTransport Namespace BypassEPSS 0.3%CVE-2026-35051HIGHTraefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authEPSS 0.3%