Vulnerabilidades en Traefik

66 resultados
Análisis Vexday

Traefik possui apenas 1 vulnerabilidade registrada na base, publicada recentemente (últimos 90 dias), classificada como CWE-400 (Uncontrolled Resource Consumption) e sem crítica CVSS. Nenhuma exploração ativa em campo foi detectada até o momento. O risco atual é mínimo, embora a recência da divulgação justifique monitoramento próximo.

CVE-2022-23632HIGHTraefik skips the router TLS configuration when the host header is an FQDNEPSS 1.7%CVE-2024-45410CRITICALHTTP client can remove the X-Forwarded headers in TraefikEPSS 1.5%CVE-2023-47633HIGHUncontrolled Resource Consumption in TraefikEPSS 1.3%CVE-2022-39271HIGHTraefik HTTP/2 connections management could cause a denial of serviceEPSS 1.1%CVE-2025-54386HIGHTraefik's Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code ExecutionEPSS 1.1%CVE-2021-32813MEDIUMDrop Headers via Malicious Connection HeaderEPSS 1.1%CVE-2023-29013HIGHHTTP header parsing could cause a deny of serviceEPSS 1.1%CVE-2024-28869HIGHPossible denial of service vulnerability with Content-length header in TraefikEPSS 1.0%CVE-2022-23469LOWAuthorization header displayed in the debug logsEPSS 1.0%CVE-2025-47952LOWTraefik allows path traversal using url encodingEPSS 0.9%CVE-2025-32431HIGHTraefik has a possible vulnerability with the path matchersEPSS 0.9%CVE-2026-25949HIGHTraefik: TCP readTimeout bypass via STARTTLS on PostgresEPSS 0.8%CVE-2023-47124MEDIUMDenial of service whith ACME HTTPChallenge in TraefikEPSS 0.8%CVE-2026-48020HIGHTraefik StripPrefix Route-Level Auth Bypass via Path NormalizationEPSS 0.8%CVE-2023-54365HIGHTraefik - Denial of Service via HTTP/2 Request HandlingEPSS 0.8%CVE-2026-40912HIGHTraefik: StripPrefixRegex auth bypass via Path/RawPath desyncEPSS 0.7%CVE-2026-26999HIGHTraefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)EPSS 0.7%CVE-2026-71324HIGHTraefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolEPSS 0.7%CVE-2026-85595CRITICALTraefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuthEPSS 0.7%CVE-2026-88010MEDIUMTraefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracleEPSS 0.7%