Vulnerabilidades em traefik

66 resultados
Análise Vexday

Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.

CVE-2026-26999HIGHTraefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS)EPSS 0.5%CVE-2026-67309HIGHTraefik v3.7.0 Path Traversal via RewriteTarget Authentication BypassEPSS 0.5%CVE-2022-46153HIGHRoutes exposed with an empty TLSOption in traefikEPSS 0.5%CVE-2026-71324HIGHTraefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolEPSS 0.5%CVE-2026-39858HIGHTraefik: Forwarded alias spoofing top pre-auth decision bypassEPSS 0.5%CVE-2026-33433MEDIUMTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldEPSS 0.5%CVE-2026-44774MEDIUMTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseEPSS 0.5%CVE-2026-29054HIGHTraefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)EPSS 0.5%CVE-2026-32695MEDIUMTraefik has Knative Ingress Rule Injection that Allows Host Restriction BypassEPSS 0.5%CVE-2026-26998MEDIUMTraefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS)EPSS 0.5%CVE-2026-41181MEDIUMTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page serviceEPSS 0.4%CVE-2026-85595CRITICALTraefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuthEPSS 0.4%CVE-2026-88877CRITICALTraefik v3.7.0 Authentication Bypass via from-to-www-redirectEPSS 0.4%CVE-2026-54762MEDIUMTraefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsEPSS 0.4%CVE-2026-65600HIGHTraefik before v2.11.52 Authentication Bypass via ReplacePathRegexEPSS 0.4%CVE-2026-32305HIGHTraefik mTLS bypass via fragmented ClientHello SNI extraction failureEPSS 0.4%CVE-2024-52003MEDIUMX-Forwarded-Prefix Header still allows for Open Redirect in traefikEPSS 0.4%CVE-2026-32595MEDIUMTraefik: BasicAuth Middleware Timing Attack Allows Username EnumerationEPSS 0.4%CVE-2026-41263MEDIUMTraefik: BasicAuth middleware: timing side-channel vulnerabilityEPSS 0.4%CVE-2026-54761MEDIUMTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesEPSS 0.4%