CVE-2026-88010
- EPSS 0.69%
- Veröffentlicht 22.09.2026 15:38:25
- Zuletzt bearbeitet 24.09.2026 21:22:19
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in pkg/middlewares/auth/basic_auth.go constructs the BasicAuth singleflight key from the submitted password and stored secret. Concurrent requests...
CVE-2026-88012
- EPSS 0.3%
- Veröffentlicht 10.09.2026 15:35:12
- Zuletzt bearbeitet 14.09.2026 20:00:02
Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply entryPoints..transport.respondingTimeouts.readTimeout because the timeout is enforced on a TCP connection and the HTT...
CVE-2026-88011
- EPSS 0.25%
- Veröffentlicht 10.09.2026 15:31:55
- Zuletzt bearbeitet 15.09.2026 15:17:24
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go tr...
CVE-2026-88009
- EPSS 0.34%
- Veröffentlicht 10.09.2026 15:01:56
- Zuletzt bearbeitet 14.09.2026 19:59:14
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing...
CVE-2026-88008
- EPSS 0.36%
- Veröffentlicht 10.09.2026 14:57:06
- Zuletzt bearbeitet 14.09.2026 19:59:04
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the bac...
CVE-2026-88007
- EPSS 0.37%
- Veröffentlicht 10.09.2026 14:47:28
- Zuletzt bearbeitet 14.09.2026 19:58:52
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a ...
CVE-2026-88004
- EPSS 0.29%
- Veröffentlicht 10.09.2026 14:33:41
- Zuletzt bearbeitet 14.09.2026 19:58:45
Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy, underscoreHeadersStrategy, and forwardedHeaders inspect req.Header but not req.Trailer, allowing an unauthentic...
CVE-2026-88879
- EPSS 0.27%
- Veröffentlicht 10.09.2026 13:05:30
- Zuletzt bearbeitet 14.09.2026 19:58:33
Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are canonicalized only on dashes, so X-Auth-User, X_Auth_User and X.Auth.User are treated as three distinct headers b...
CVE-2026-88878
- EPSS 0.3%
- Veröffentlicht 10.09.2026 13:05:30
- Zuletzt bearbeitet 14.09.2026 19:58:08
Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by default at 60s — a...
CVE-2026-88877
- EPSS 0.44%
- Veröffentlicht 10.09.2026 13:05:29
- Zuletzt bearbeitet 14.09.2026 19:57:56
Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles Ingresses that carry both an authentication annotation and the nginx.ingress.kubernetes.io/from-to-www-redirect ...