github.com/traefik/traefik vulnerabilities
CVEs whose affected-version data names the github.com/traefik/traefik package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
14 CVEsRSS
CVE-2026-54764Medium· 5.8Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
CVE-2026-65600Critical· 9.1Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-53622HighTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVE-2026-40912High· 8.2Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
GHSA-7jmw-8259-q9jxMediumTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
GO-2024-2726NoneTraefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
GHSA-f7cq-5v43-8pwpMedium· 5.3Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
CVE-2023-54365MediumTraefik vulnerable to HTTP/2 request causing denial of service
Traefik vulnerable to HTTP/2 request causing denial of service
CVE-2020-15129Medium· 6.1PoCTraefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
CVE-2021-32813Medium· 4.8Header dropping in traefik
Header dropping in traefik