Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Traefik — Vulnerabilities & Security Advisories 52

Browse all 52 CVE security advisories affecting Traefik. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Traefik functions as an open-source edge router and reverse proxy, primarily designed to simplify the deployment of microservices by automatically discovering and configuring backend services. Its architecture focuses on dynamic configuration, allowing it to integrate seamlessly with container orchestration platforms like Docker and Kubernetes. Historically, the software has been susceptible to several critical vulnerability classes, including remote code execution, path traversal, and privilege escalation flaws. These issues often stem from improper input validation or insufficient access controls within its HTTP middleware and entry point configurations. With thirty-three recorded CVEs, recent incidents have highlighted risks related to unauthorized access to the dashboard and potential denial-of-service conditions. While the project maintains an active security response process, the high volume of disclosed flaws underscores the complexity of managing dynamic routing logic in distributed environments, requiring diligent patching and strict configuration hygiene to mitigate exposure.

Top products by Traefik: traefik
High2026-08-07
Fix cross-namespace service reference check in Kubernetes CRD provider · traefik/traefik@65ebf4b · GitHub
MediumCVE-2026-71252026-08-07
`allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef · Advisory · traefik/traefik · GitHub
Unknown2026-08-07
Release v3.6.25 · traefik/traefik · GitHub
Unknown2026-08-07
Release v3.7.10 · traefik/traefik · GitHub
CriticalCVE-2025-713242026-08-07
Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool · Advisory · traefik/traef
High2026-08-07
Defer the CONNECT payload until the backend accepts the tunnel by sdelicata · Pull Request #13542 · traefik/traefik · Gi
High2026-08-07
Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy by sdelicata · Pull Request #13543 · tra
Medium2026-08-07
Do not add back CONNECT requests to the pool · traefik/traefik@0807b6d · GitHub
High2026-08-07
Discard CONNECT body in forwardauth and reject CONNECT requests with … · traefik/traefik@04d36f2 · GitHub
High2026-08-07
Defer the CONNECT payload until the backend accepts the tunnel · traefik/traefik@94a7508 · GitHub
UnknownGHSA-3ccp-42qp-hq962026-08-07
Release v3.7.9 · traefik/traefik · GitHub
High2026-08-07
Fix auth singleflight key collision · traefik/traefik@b5ace8e · GitHub
High2026-08-01
Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass · Advisory · traefik/trae
Unknown2026-07-22
Prepare release v3.7.5 · traefik/traefik@26c96a3 · GitHub
Medium2026-07-22
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion · Advisory · traefik/traefik · GitHub
Medium2026-07-22
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass · Advisory · traefik/traefik · GitHub
High2026-07-07
Add an option to remove request headers with underscores by youkoulayley · Pull Request #13262 · traefik/traefik · GitHu
High2026-07-07
Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in Bas
Medium2026-07-07
Avoid collisions for Gateway API services names by rtribotte · Pull Request #13367 · traefik/traefik · GitHub
UnknownCVE-2026-547632026-07-07
Release v3.7.6 · traefik/traefik · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with Traefik. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.