CVE-2026-32595
- EPSS 0.01%
- Veröffentlicht 20.03.2026 10:08:41
- Zuletzt bearbeitet 20.03.2026 13:37:50
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middle...
CVE-2026-32305
- EPSS 0.02%
- Veröffentlicht 20.03.2026 10:01:13
- Zuletzt bearbeitet 20.03.2026 13:37:50
Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS Clie...
CVE-2026-29777
- EPSS 0.01%
- Veröffentlicht 11.03.2026 16:16:40
- Zuletzt bearbeitet 19.03.2026 20:26:04
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.10, A tenant with write access to an HTTPRoute resource can inject backtick-delimited rule tokens into Traefik's router rule language via unsanitized header or query parameter match val...
CVE-2026-29054
- EPSS 0.01%
- Veröffentlicht 05.03.2026 16:18:49
- Zuletzt bearbeitet 06.03.2026 15:26:20
Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X-Forwarded headers. When Traefik processes HTTP/1.1...
CVE-2026-26999
- EPSS 0.02%
- Veröffentlicht 05.03.2026 16:15:36
- Zuletzt bearbeitet 06.03.2026 15:27:05
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing TLS handshake on TCP routers. When Traefik processes a TLS connection on a TCP router, the read deadline u...
CVE-2026-26998
- EPSS 0.03%
- Veröffentlicht 05.03.2026 16:15:05
- Zuletzt bearbeitet 06.03.2026 15:27:01
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the re...
CVE-2026-25949
- EPSS 0.02%
- Veröffentlicht 12.02.2026 20:01:19
- Zuletzt bearbeitet 20.02.2026 18:44:41
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte...
CVE-2026-22045
- EPSS 0.02%
- Veröffentlicht 15.01.2026 22:44:05
- Zuletzt bearbeitet 23.01.2026 19:29:05
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go rout...
CVE-2025-66491
- EPSS 0.01%
- Veröffentlicht 09.12.2025 00:38:39
- Zuletzt bearbeitet 02.01.2026 21:12:07
Traefik is an HTTP reverse proxy and load balancer. Versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to "on" (intending to enable backend TLS cert...
CVE-2025-66490
- EPSS 0.02%
- Veröffentlicht 09.12.2025 00:35:26
- Zuletzt bearbeitet 06.03.2026 15:25:34
Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests using PathPrefix, Path or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containin...