Vulnerabilidades en traefik

52 resultados
Análisis Vexday

Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.

CVE-2026-67309HIGHTraefik v3.7.0 Path Traversal via RewriteTarget Authentication BypassEPSS 0.5%CVE-2022-46153HIGHRoutes exposed with an empty TLSOption in traefikEPSS 0.5%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.5%CVE-2026-33433MEDIUMTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldEPSS 0.5%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%CVE-2026-29054HIGHTraefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)EPSS 0.5%CVE-2026-32695MEDIUMTraefik has Knative Ingress Rule Injection that Allows Host Restriction BypassEPSS 0.5%CVE-2026-26998MEDIUMTraefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS)EPSS 0.5%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.4%CVE-2026-65600HIGHTraefik before v2.11.52 Authentication Bypass via ReplacePathRegexEPSS 0.4%CVE-2026-54762MEDIUMTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsEPSS 0.4%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.4%CVE-2024-52003MEDIUMX-Forwarded-Prefix Header still allows for Open Redirect in traefikEPSS 0.4%CVE-2026-32595MEDIUMTraefik: BasicAuth Middleware Timing Attack Allows Username EnumerationEPSS 0.4%CVE-2025-66490MEDIUMTraefik doesn't Prevent Path Normalization Bypass in Router + Middleware RulesEPSS 0.4%CVE-2026-41263MEDIUMTraefik: BasicAuth middleware: timing side-channel vulnerabilityEPSS 0.4%CVE-2026-71327HIGHTraefik: Gateway API route identity collision allows cross-namespace backend hijackingEPSS 0.4%CVE-2026-71326LOWTraefik: BasicAuth singleflight key collision allows authenticated identity spoofingEPSS 0.4%CVE-2026-22045MEDIUMTraefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallEPSS 0.3%CVE-2026-54761MEDIUMTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesEPSS 0.3%