GHSA-7jmw-8259-q9jxMedium▾ SunlitTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
There is a vulnerability in Go managing various Is methods (IsPrivate, IsLoopback, etc) for IPv4-mapped IPv6 addresses.
They didn't work as expected returning false for addresses which would return true in their traditional IPv4 forms.
No workaround.
If you have any questions or comments about this advisory, please open an issue.
github.com/traefik/traefik/v3 >= 3.0.0-beta3, < 3.0.2github.com/traefik/traefik/v2 < 2.11.4github.com/traefik/traefik < 2.11.4Upgrade to a patched release:
github.com/traefik/traefik/v3 3.0.2github.com/traefik/traefik/v2 2.11.4github.com/traefik/traefik 2.11.4Connected by shared product, vendor, weakness, or advisory.
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
CVE-2025-66491Medium· 5.9Traefik Inverted TLS Verification Logic in ingress-nginx Provider
CVE-2026-32695MediumTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
GHSA-3wqc-mwfx-672pHigh· 7.5Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
CVE-2024-28869High· 7.5Traefik vulnerable to denial of service with Content-length header