Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

traefik — Vulnerabilities & Security Advisories 45

All 45 CVE vulnerabilities found in traefik, with AI-generated Chinese analysis, references, and POCs.

This page catalogs Common Weakness Enumerations associated with the Traefik reverse proxy and load balancer product. It aggregates security vulnerabilities discovered within the software ecosystem, focusing on architectural flaws, configuration errors, and implementation defects that affect the integrity and availability of the service. The database collects reported issues spanning from the early releases of the project through recent updates, ensuring a comprehensive historical view of security incidents. Users can utilize this resource to track vendor advisories and understand how specific weakness classes manifest within Traefik’s deployment scenarios. It serves as a reference for looking up the product’s vulnerability history, allowing administrators and security researchers to analyze patterns in reported flaws over time. The page organizes entries by severity and component, facilitating deeper investigation into how these weaknesses impact container orchestration environments. By reviewing the aggregated data, stakeholders can better assess risk exposure and prioritize remediation efforts based on the specific characteristics of each vulnerability. This structured approach helps in maintaining a secure infrastructure by providing clear insights into the historical security posture of the Traefik software. The information presented is intended to support informed decision-making regarding patch management and system hardening strategies without promoting any specific vendor or solution.

Vendor: traefik

CVE IDTitleCVSSSeverityPublished
CVE-2025-32431 Traefik has a possible vulnerability with the path matchers CWE-22 5.9 -2025-04-21
CVE-2024-52003 X-Forwarded-Prefix Header still allows for Open Redirect in traefik CWE-601 5.3 -2024-11-29
CVE-2024-45410 HTTP client can remove the X-Forwarded headers in Traefik CWE-345 9.8 Critical2024-09-19
CVE-2024-39321 Traefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes CWE-639 7.5 High2024-07-05
CVE-2024-28869 Possible denial of service vulnerability with Content-length header in Traefik CWE-755 7.5 High2024-04-12
CVE-2023-47633 Uncontrolled Resource Consumption in Traefik CWE-400 7.5 High2023-12-04
CVE-2023-47106 Incorrect processing of fragment in the URL leads to Authorization Bypass in Traefik CWE-20 4.8 Medium2023-12-04
CVE-2023-47124 Denial of service whith ACME HTTPChallenge in Traefik CWE-772 5.9 Medium2023-12-04
CVE-2023-29013 HTTP header parsing could cause a deny of service CWE-400 7.5 High2023-04-14
CVE-2022-46153 Routes exposed with an empty TLSOption in traefik CWE-295 8.1 High2022-12-08
CVE-2022-23469 Authorization header displayed in the debug logs CWE-200 3.5 Low2022-12-08
CVE-2022-39271 Traefik HTTP/2 connections management could cause a denial of service CWE-400 7.5 High2022-10-11
CVE-2022-23632 Traefik skips the router TLS configuration when the host header is an FQDN CWE-295 7.4 High2022-02-17
CVE-2021-32813 Drop Headers via Malicious Connection Header CWE-913 4.8 Medium2021-08-03
CVE-2020-15129 Open redirect in Traefik CWE-601 6.1 Medium2020-07-30

All 45 known CVE vulnerabilities affecting traefik with full Chinese analysis, references, and POCs where available.