VulnSea

github.com/traefik/traefik/v3 vulnerabilities

CVEs whose affected-version data names the github.com/traefik/traefik/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

26 CVEsRSS

CVE-2026-54764Medium· 5.8
1mo ago

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.28%via GHSA
CVE-2026-54765Medium
1mo ago

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.28%via GHSA
CVE-2026-65600Critical· 9.1
1mo ago

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.41%via GHSA
CVE-2026-54763High
1mo ago

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Twilighttraefik · github.com/traefik/traefik/v2EPSS 0.21%via GHSA
CVE-2026-65602Medium
1mo ago

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass

Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.18%via GHSA
CVE-2026-54762High· 8.6
3mo ago

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.43%via OSV
CVE-2026-54761High· 7.1PoC
3mo ago

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Midnighttraefik · github.com/traefik/traefik/v3EPSS 0.37%via OSV
CVE-2026-48020HighPoC
3mo ago

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization

Midnighttraefik · github.com/traefik/traefik/v2EPSS 0.78%via GHSA
CVE-2026-41181Medium
4mo ago

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service

Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.45%via OSV
CVE-2026-40912High· 8.2
5mo ago

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync

Twilighttraefik · github.com/traefik/traefik/v3EPSS 0.77%via OSV
GHSA-46wh-3698-f2cxHigh
5mo ago

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)

Twilighttraefik · github.com/traefik/traefik/v2via OSV
CVE-2026-32695Medium
5mo ago

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.46%via OSV
CVE-2025-66491Medium· 5.9
9mo ago

Traefik Inverted TLS Verification Logic in ingress-nginx Provider

Traefik Inverted TLS Verification Logic in ingress-nginx Provider

Sunlittraefik · github.com/traefik/traefik/v3EPSS 0.22%via OSV
GHSA-3wqc-mwfx-672pHigh· 7.5
1y ago

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability

Twilighttraefik · github.com/traefik/traefik/v3via OSV
GO-2024-2941None
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GHSA-rvj4-q8q5-8grfMedium· 5.5
2y ago

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability

Sunlittraefik · github.com/traefik/traefik/v3via OSV
GO-2024-2917None
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GHSA-7jmw-8259-q9jxMedium
2y ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses

Sunlittraefik · github.com/traefik/traefik/v3via OSV
GO-2024-2880None
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GO-2024-2726None
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

Sunlittraefik · github.com/traefik/traefikvia OSV
GHSA-f7cq-5v43-8pwpMedium· 5.3
2y ago

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop

Sunlittraefik · github.com/traefik/traefik/v2via OSV
GHSA-7f4j-64p6-5h5vMedium
2y ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http

Traefik affected by HTTP/2 CONTINUATION flood in net/http

Sunlittraefik · github.com/traefik/traefik/v2via OSV
CVE-2024-28869High· 7.5
2y ago

Traefik vulnerable to denial of service with Content-length header

Traefik vulnerable to denial of service with Content-length header

Twilighttraefik · github.com/traefik/traefik/v3EPSS 1.0%via OSV
CVE-2023-47106Medium· 6.5
2y ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass

Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.63%via OSV
CVE-2023-47124Medium· 5.9
2y ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Traefik vulnerable to potential DDoS via ACME HTTPChallenge

Sunlittraefik · github.com/traefik/traefik/v2EPSS 0.79%via OSV
CVE-2023-47633High· 7.5
2y ago

Traefik docker container using 100% CPU

Traefik docker container using 100% CPU

Twilighttraefik · github.com/traefik/traefik/v2EPSS 1.3%via OSV
github.com/traefik/traefik/v3 vulnerabilities (CVEs) · VulnSea