Traefik has 55 CVEs on record between 2021 and 2026. Disclosure cadence is accelerating: 25 in the last 90 days against 9 in the 90 before. The busiest recent month was September 2026 with 14. The median CVSS is 7.5 (high), with 9 rated critical. None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (8) and CWE-770 (5). Most affected products: traefik (24), github.com/traefik/traefik/v2 (15), github.com/traefik/traefik/v3 (10).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 25 prev 9
Products
- traefik 24
- github.com/traefik/traefik/v2 15
- github.com/traefik/traefik/v3 10
- github.com/traefik/traefik 6
Worst active — by depth score
CVE-2026-88877Critical· 9.8Traefik is a HTTP reverse proxy and load balancer66CVE-2026-85596Critical· 9.8Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider54CVE-2026-85595Critical· 9.8Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection54CVE-2026-85594Critical· 9.8Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider54CVE-2026-48020HighTraefik has a StripPrefix Route-Level Auth Bypass via Path Normalization53
Traefik vulnerabilities
CVEs affecting Traefik, newest first. Open any entry for full detail, references, and exploit status.
55 CVEsRSS
CVE-2026-53622HighTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
CVE-2026-48020HighPoCTraefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
Traefik has a StripPrefix Route-Level Auth Bypass via Path Normalization
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2026-40912High· 8.2Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-32695MediumTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
CVE-2026-25949High· 7.5Traefik is an HTTP reverse proxy and load balancer
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sendi…
CVE-2025-66491Medium· 5.9Traefik Inverted TLS Verification Logic in ingress-nginx Provider
Traefik Inverted TLS Verification Logic in ingress-nginx Provider
GHSA-3wqc-mwfx-672pHigh· 7.5Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
Traefik affected by Go oauth2/jws Improper Validation of Syntactic Correctness of Input vulnerability
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
GHSA-rvj4-q8q5-8grfMedium· 5.5ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
ACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
GHSA-7jmw-8259-q9jxMediumTraefik has unexpected behavior with IPv4-mapped IPv6 addresses
Traefik has unexpected behavior with IPv4-mapped IPv6 addresses
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik
GO-2024-2726NoneTraefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik
GHSA-f7cq-5v43-8pwpMedium· 5.3Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
GHSA-7f4j-64p6-5h5vMediumTraefik affected by HTTP/2 CONTINUATION flood in net/http
Traefik affected by HTTP/2 CONTINUATION flood in net/http
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge
Traefik vulnerable to potential DDoS via ACME HTTPChallenge
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
Traefik docker container using 100% CPU
CVE-2023-29013High· 7.5Traefik HTTP header parsing could cause a denial of service
Traefik HTTP header parsing could cause a denial of service
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs
Traefik may display authorization header in the debug logs
CVE-2022-46153Medium· 6.5Traefik routes exposed with an empty TLSOption
Traefik routes exposed with an empty TLSOption
CVE-2020-15129Medium· 6.1PoCTraefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
CVE-2021-32813Medium· 4.8Header dropping in traefik
Header dropping in traefik