- Products & ServicesProducts & Services
- SolutionsSolutions
- PricingPricing
- CompanyCompany
- ResourcesResources
en
en
As of 09/13/2026, traefik recorded 30 security vulnerabilities in the last 90 days across 1 products, including 18 rated High or above and 0 known exploited vulnerabilities (KEV) that should be prioritized for immediate remediation.
Over the last 90 days, traefik had the most security vulnerabilities in the traefik ecosystem, with 30 vulnerabilities—approximately 100% of the provider's total vulnerabilities during this period.
| Vulnerability | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-88012Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityMedium |
CVE-2026-88011Traefik: ForwardAuth identity spoofing via dot-form header alias | Exploitation statusNot confirmed | FixNot confirmed | Affected producttraefik | Published09/10/2026 | SeverityMedium |
CVE-2026-88009Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityHigh |
CVE-2026-88008Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityHigh |
CVE-2026-88007Traefik HTTP/3 Backend NTLM Connection Reuse | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityCritical |
CVE-2026-88004Traefik entrypoint header-name sanitization bypassed via request trailers | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityHigh |
CVE-2026-88879Traefik before v2.11.56 Identity Spoofing via Header Alias | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityMedium |
CVE-2026-88878Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityMedium |
CVE-2026-88877Traefik v3.7.0 Authentication Bypass via from-to-www-redirect | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/10/2026 | SeverityCritical |
CVE-2026-85597Traefik before v2.11.55 and v3.0.0 through v3.7.10 mTLS Bypass via TLS Option Conflict | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/04/2026 | SeverityHigh |
CVE-2026-85596Traefik v3.7 Authentication Bypass via TLS Option Conflict | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/04/2026 | SeverityHigh |
CVE-2026-85595Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/04/2026 | SeverityCritical |
CVE-2026-85594Traefik v3.7.1 crossProviderNamespaces Bypass via Service Middleware | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published09/04/2026 | SeverityHigh |
CVE-2026-71327Traefik: Gateway API route identity collision allows cross-namespace backend hijacking | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/06/2026 | SeverityHigh |
CVE-2026-71326Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/06/2026 | SeverityLow |
CVE-2026-71325Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/06/2026 | SeverityMedium |
CVE-2026-71324Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/06/2026 | SeverityHigh |
CVE-2026-67309Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/01/2026 | SeverityHigh |
CVE-2026-65602Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/22/2026 | SeverityMedium |
CVE-2026-65601Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/22/2026 | SeverityMedium |
CVE-2026-65600Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/22/2026 | SeverityHigh |
CVE-2026-54763Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/06/2026 | SeverityHigh |
CVE-2026-54765Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/06/2026 | SeverityMedium |
CVE-2026-54764ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published07/06/2026 | SeverityMedium |
CVE-2026-54762Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityMedium |
CVE-2026-54761Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityMedium |
CVE-2026-53622Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityHigh |
CVE-2026-48491Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityHigh |
CVE-2026-48020Traefik StripPrefix Route-Level Auth Bypass via Path Normalization | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityHigh |
CVE-2023-54365Traefik - Denial of Service via HTTP/2 Request Handling | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published06/23/2026 | SeverityHigh |
CVE-2026-44774Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published05/15/2026 | SeverityMedium |
CVE-2026-41181Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published05/15/2026 | SeverityMedium |
CVE-2026-41263Traefik: BasicAuth middleware: timing side-channel vulnerability | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/30/2026 | SeverityMedium |
CVE-2026-40912Traefik: StripPrefixRegex auth bypass via Path/RawPath desync | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/30/2026 | SeverityHigh |
CVE-2026-39858Traefik: Forwarded alias spoofing top pre-auth decision bypass | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/30/2026 | SeverityHigh |
CVE-2026-35051Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/30/2026 | SeverityHigh |
CVE-2026-41174Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/30/2026 | SeverityMedium |
CVE-2026-33433Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published03/27/2026 | SeverityMedium |
CVE-2026-32695Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published03/27/2026 | SeverityMedium |
CVE-2026-32595Traefik: BasicAuth Middleware Timing Attack Allows Username Enumeration | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/20/2026 | SeverityMedium |
CVE-2026-32305Traefik mTLS bypass via fragmented ClientHello SNI extraction failure | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/20/2026 | SeverityHigh |
CVE-2026-29777Traefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/11/2026 | SeverityMedium |
CVE-2026-29054Traefik: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`) | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/05/2026 | SeverityHigh |
CVE-2026-26999Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (slowloris doS) | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/05/2026 | SeverityHigh |
CVE-2026-26998Traefik: unbounded io.ReadAll on auth server response body causes OOM denial of service(DOS) | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published03/05/2026 | SeverityMedium |
CVE-2026-25949Traefik: TCP readTimeout bypass via STARTTLS on Postgres | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published02/12/2026 | SeverityHigh |
CVE-2026-22045Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published01/15/2026 | SeverityMedium |
CVE-2025-66491Traefik has Inverted TLS Verification Logic in its ingress-nginx Provider | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published12/09/2025 | SeverityMedium |
CVE-2025-66490Traefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules | Exploitation statusPublic exploit | FixYes | Affected producttraefik | Published12/09/2025 | SeverityMedium |
CVE-2025-54386Traefik's Client Plugin is Vulnerable to Path Traversal, Arbitrary File Overwrites and Remote Code Execution | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published08/01/2025 | SeverityHigh |
CVE-2025-47952Traefik allows path traversal using url encoding | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published05/30/2025 | SeverityLow |
CVE-2025-32431Traefik has a possible vulnerability with the path matchers | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/21/2025 | SeverityHigh |
CVE-2024-52003X-Forwarded-Prefix Header still allows for Open Redirect in traefik | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published11/29/2024 | SeverityMedium |
CVE-2024-45410HTTP client can remove the X-Forwarded headers in Traefik | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published09/19/2024 | SeverityCritical |
CVE-2024-39321Traefik vulnerable to bypassing IP allow-lists via HTTP/3 early data requests in QUIC 0-RTT handshakes | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published07/05/2024 | SeverityHigh |
CVE-2024-28869Possible denial of service vulnerability with Content-length header in Traefik | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published04/12/2024 | SeverityHigh |
CVE-2023-47633Uncontrolled Resource Consumption in Traefik | Exploitation statusPublic exploit | FixNot confirmed | Affected producttraefik | Published12/04/2023 | SeverityHigh |
CVE-2023-47106Incorrect processing of fragment in the URL leads to Authorization Bypass in Traefik | Exploitation statusNot confirmed | FixNot confirmed | Affected producttraefik | Published12/04/2023 | SeverityMedium |
CVE-2023-47124Denial of service whith ACME HTTPChallenge in Traefik | Exploitation statusNot confirmed | FixNot confirmed | Affected producttraefik | Published12/04/2023 | SeverityMedium |
CVE-2023-44487 | Exploitation statusKEV | FixNot confirmed | Affected productNot confirmed | Published10/10/2023 | SeverityHigh |
CVE-2023-29013HTTP header parsing could cause a deny of service | Exploitation statusNot known exploited | FixYes | Affected producttraefik | Published04/14/2023 | SeverityHigh |
CVE-2022-46153Routes exposed with an empty TLSOption in traefik | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published12/08/2022 | SeverityHigh |
CVE-2022-23469Authorization header displayed in the debug logs | Exploitation statusPublic exploit | FixNot confirmed | Affected producttraefik | Published12/08/2022 | SeverityLow |
CVE-2022-39271Traefik HTTP/2 connections management could cause a denial of service | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published10/11/2022 | SeverityHigh |
CVE-2022-23632Traefik skips the router TLS configuration when the host header is an FQDN | Exploitation statusNot known exploited | FixNot confirmed | Affected producttraefik | Published02/17/2022 | SeverityHigh |
CVE-2021-32813Drop Headers via Malicious Connection Header | Exploitation statusNot confirmed | FixYes | Affected producttraefik | Published08/03/2021 | SeverityMedium |
CVE-2020-15129Open redirect in Traefik | Exploitation statusNot confirmed | FixNot confirmed | Affected producttraefik | Published07/30/2020 | SeverityMedium |
CVE-2019-20894 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published07/02/2020 | SeverityUnknown |
CVE-2020-9321 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published03/16/2020 | SeverityUnknown |
CVE-2019-12452 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published05/29/2019 | SeverityUnknown |
CVE-2018-15598 | Exploitation statusNot confirmed | FixNot confirmed | Affected productNot confirmed | Published08/21/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan