CVE-2026-85597
- EPSS 0.23%
- Veröffentlicht 04.09.2026 11:30:00
- Zuletzt bearbeitet 16.09.2026 20:42:21
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Att...
CVE-2026-85596
- EPSS 0.22%
- Veröffentlicht 04.09.2026 11:30:00
- Zuletzt bearbeitet 16.09.2026 20:42:34
Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/auth-tls-secret annotation was named after the Ingre...
CVE-2026-85595
- EPSS 0.41%
- Veröffentlicht 04.09.2026 11:29:59
- Zuletzt bearbeitet 16.09.2026 20:42:43
Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead of rejection. Attackers can compute a valid diges...
CVE-2026-85594
- EPSS 0.22%
- Veröffentlicht 04.09.2026 11:29:58
- Zuletzt bearbeitet 16.09.2026 20:42:53
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A namespace-limited tenant excluded from the allowlist c...
CVE-2026-71325
- EPSS 0.13%
- Veröffentlicht 06.08.2026 22:18:29
- Zuletzt bearbeitet 16.09.2026 20:46:01
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the ser...
CVE-2026-71324
- EPSS 0.55%
- Veröffentlicht 06.08.2026 22:18:29
- Zuletzt bearbeitet 16.09.2026 20:46:12
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.53, 3.6.24, and 3.7.9, Traefik's default HTTP reverse proxy forwards a plain HTTP/2 or HTTP/3 CONNECT request and its body to an HTTP/1.1 upstream through a shared net/http...
CVE-2026-71326
- EPSS 0.36%
- Veröffentlicht 06.08.2026 22:18:29
- Zuletzt bearbeitet 16.09.2026 20:44:44
Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.6.25 and 3.7.10, Traefik's BasicAuth middleware in pkg/middlewares/auth/basic_auth.go deduplicates concurrent password checks with a singleflight key built from the d...
CVE-2026-71327
- EPSS 0.36%
- Veröffentlicht 06.08.2026 22:18:29
- Zuletzt bearbeitet 16.09.2026 20:44:53
Traefik is an open source HTTP reverse proxy and load balancer. From 3.0.0 until 3.6.25 and 3.7.10, Traefik's Kubernetes Gateway API provider in pkg/provider/kubernetes/gateway/httproute.go, grpcroute.go, tcproute.go, and tlsroute.go builds HTTPRoute...
CVE-2026-67309
- EPSS 0.49%
- Veröffentlicht 01.08.2026 12:22:18
- Zuletzt bearbeitet 16.09.2026 20:45:02
Traefik versions >= v3.7.0 and <= v3.7.7 contain a path traversal vulnerability in the Kubernetes Ingress NGINX provider's RewriteTarget middleware (generated from the nginx.ingress.kubernetes.io/rewrite-target annotation). When an Ingress path uses ...
CVE-2026-65602
- EPSS 0.19%
- Veröffentlicht 22.07.2026 11:21:48
- Zuletzt bearbeitet 06.08.2026 15:18:22
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allowlist was only enforced for HTTP serversTransport references). A low-privilege...