Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

traefik — Vulnerabilities & Security Advisories 53

All 53 CVE vulnerabilities found in traefik, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations associated with the Traefik reverse proxy and load balancer product. It aggregates security vulnerabilities discovered within the software ecosystem, focusing on architectural flaws, configuration errors, and implementation defects that affect the integrity and availability of the service. The database collects reported issues spanning from the early releases of the project through recent updates, ensuring a comprehensive historical view of security incidents. Users can utilize this resource to track vendor advisories and understand how specific weakness classes manifest within Traefik’s deployment scenarios. It serves as a reference for looking up the product’s vulnerability history, allowing administrators and security researchers to analyze patterns in reported flaws over time. The page organizes entries by severity and component, facilitating deeper investigation into how these weaknesses impact container orchestration environments. By reviewing the aggregated data, stakeholders can better assess risk exposure and prioritize remediation efforts based on the specific characteristics of each vulnerability. This structured approach helps in maintaining a secure infrastructure by providing clear insights into the historical security posture of the Traefik software. The information presented is intended to support informed decision-making regarding patch management and system hardening strategies without promoting any specific vendor or solution.

Vendor: traefik

CVE IDTitleCVSSSeverityPublished
CVE-2026-71327 Traefik: Gateway API route identity collision allows cross-namespace backend hijacking CWE-694 7.6 High2026-08-06
CVE-2026-71326 Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing CWE-287 2.1 Low2026-08-06
CVE-2026-71325 Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef CWE-653 4.8 Medium2026-08-06
CVE-2026-71324 Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool CWE-444 7.0 High2026-08-06
CVE-2026-67309 Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass CWE-22 7.8 High2026-08-01
CVE-2026-65602 Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass CWE-863 5.3 Medium2026-07-22
CVE-2026-65600 Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex CWE-22 7.8 High2026-07-22
CVE-2026-65601 Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef CWE-863 5.3 Medium2026-07-22
CVE-2026-54763 Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth CWE-178--2026-07-06
CVE-2026-54765 Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port CWE-284--2026-07-06
CVE-2026-54764 ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false CWE-345--2026-07-06
CVE-2026-54762 Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails CWE-636--2026-06-23
CVE-2026-54761 Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services CWE-284--2026-06-23
CVE-2026-53622 Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts CWE-288--2026-06-23
CVE-2026-48491 Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass CWE-288--2026-06-23
CVE-2026-48020 Traefik StripPrefix Route-Level Auth Bypass via Path Normalization CWE-288--2026-06-23
CVE-2023-54365 Traefik - Denial of Service via HTTP/2 Request Handling CWE-400 7.5 High2026-06-23
CVE-2026-44774 Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false CWE-284--2026-05-15
CVE-2026-41181 Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service CWE-201--2026-05-15
CVE-2026-41263 Traefik: BasicAuth middleware: timing side-channel vulnerability CWE-208 3.7 -2026-04-30
CVE-2026-40912 Traefik: StripPrefixRegex auth bypass via Path/RawPath desync CWE-706 8.2 -2026-04-30
CVE-2026-39858 Traefik: Forwarded alias spoofing top pre-auth decision bypass CWE-290 9.8 -2026-04-30
CVE-2026-35051 Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth CWE-345 9.1 -2026-04-30
CVE-2026-41174 Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding CWE-863 9.3 -2026-04-30
CVE-2026-33433 Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField CWE-290 8.1 -2026-03-27
CVE-2026-32695 Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass CWE-74 10.0 -2026-03-27
CVE-2026-32595 Traefik: BasicAuth Middleware Timing Attack Allows Username Enumeration CWE-208 3.7 -2026-03-20
CVE-2026-32305 Traefik mTLS bypass via fragmented ClientHello SNI extraction failure CWE-287 7.5 -2026-03-20
CVE-2026-29777 Traefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values CWE-74 5.4AIMediumAI2026-03-11
CVE-2026-29054 Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`) CWE-178 7.5 High2026-03-05

All 53 known CVE vulnerabilities affecting traefik with full Chinese analysis, references, and POCs where available.