github.com/traefik/traefik/v3 vulnerabilities
CVEs whose affected-version data names the github.com/traefik/traefik/v3 package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
26 CVEsRSS
CVE-2026-54764Medium· 5.8Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
CVE-2026-54765MediumTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port
CVE-2026-65600Critical· 9.1Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
CVE-2026-54763HighTraefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
CVE-2026-65602MediumTraefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass
CVE-2026-54762High· 8.6Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails
CVE-2026-54761High· 7.1PoCTraefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services
CVE-2026-48020HighPoCTraefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2026-40912High· 8.2Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-32695MediumTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
CVE-2025-66491Medium· 5.9Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
GHSA-3wqc-mwfx-672pHigh· 7.5Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
GHSA-7jmw-8259-q9jxMediumTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
GO-2024-2726NoneTraefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
GHSA-f7cq-5v43-8pwpMedium· 5.3Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
GHSA-7f4j-64p6-5h5vMediumTraefik affected by HTTP/2 CONTINUATION flood in net/http
Traefik affected by HTTP/2 CONTINUATION flood in net/http
CVE-2024-28869High· 7.5Traefik vulnerable to denial of service with Content-length header
Traefik vulnerable to denial of service with Content-length header
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
Traefik docker container using 100% CPU