Vulnerabilidades em traefik
66 resultadosAnálise Vexday
Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.
CVE-2025-66490MEDIUMTraefik doesn't Prevent Path Normalization Bypass in Router + Middleware RulesEPSS 0.4%CVE-2026-48491HIGHTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypassEPSS 0.4%CVE-2026-71327HIGHTraefik: Gateway API route identity collision allows cross-namespace backend hijackingEPSS 0.4%CVE-2026-22045MEDIUMTraefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallEPSS 0.3%CVE-2026-88008HIGHTraefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect AuthorizationEPSS 0.3%CVE-2026-88007CRITICALTraefik HTTP/3 Backend NTLM Connection ReuseEPSS 0.3%CVE-2026-88878MEDIUMTraefik v2.8.2 through v3.6 HTTP/3 Timeout BypassEPSS 0.3%CVE-2026-88012MEDIUMTraefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unboundedEPSS 0.3%CVE-2026-65601MEDIUMTraefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRefEPSS 0.3%CVE-2026-54764MEDIUMForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falseEPSS 0.3%CVE-2026-29777MEDIUMTraefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesEPSS 0.3%CVE-2026-54765MEDIUMTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portEPSS 0.3%CVE-2026-88004HIGHTraefik entrypoint header-name sanitization bypassed via request trailersEPSS 0.3%CVE-2026-88009HIGHTraefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access loggingEPSS 0.3%CVE-2026-35051HIGHTraefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authEPSS 0.3%CVE-2026-85594HIGHTraefik v3.7.1 crossProviderNamespaces Bypass via Service MiddlewareEPSS 0.3%CVE-2026-71326LOWTraefik: BasicAuth singleflight key collision allows authenticated identity spoofingEPSS 0.3%CVE-2026-41174MEDIUMTraefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingEPSS 0.3%CVE-2026-85596HIGHTraefik v3.7 Authentication Bypass via TLS Option ConflictEPSS 0.2%CVE-2026-88011MEDIUMTraefik: ForwardAuth identity spoofing via dot-form header aliasEPSS 0.2%