VulnSea

github.com/traefik/traefik vulnerabilities

CVEs whose affected-version data names the github.com/traefik/traefik package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

14 CVEsRSS

CVE-2026-54764Medium· 5.8
1mo ago

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.28%via GHSA
CVE-2026-65600Critical· 9.1
1mo ago

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.41%via GHSA
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-53622High
3mo ago

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

TwilightTraefik · TraefikEPSS 0.63%via GHSA
CVE-2026-40912High· 8.2
5mo ago

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.77%via OSV
GO-2024-2941None
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GO-2024-2917None
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GHSA-7jmw-8259-q9jxMedium
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Sunlittraefik · github.com/traefik/traefik/v3via OSV
GO-2024-2880None
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GO-2024-2726None
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GHSA-f7cq-5v43-8pwpMedium· 5.3
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Sunlittraefik · github.com/traefik/traefik/v2via OSV
CVE-2023-54365Medium
2y ago

Traefik vulnerable to HTTP/2 request causing denial of service

Traefik vulnerable to HTTP/2 request causing denial of service

Sunlittraefik · github.com/traefik/traefikEPSS 0.77%via OSV
CVE-2020-15129Medium· 6.1PoC
4y ago

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header

Twilighttraefik · github.com/traefik/traefikEPSS 8.0%via OSV
CVE-2021-32813Medium· 4.8
5y ago

Header dropping in traefik

Header dropping in traefik

Sunlittraefik · github.com/traefik/traefik/v2EPSS 1.1%via OSV
github.com/traefik/traefik vulnerabilities (CVEs) · VulnSea