Traefik

Traefik

72 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.27%
  • Veröffentlicht 22.07.2026 11:21:47
  • Zuletzt bearbeitet 06.08.2026 15:36:09

Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, Traefik used the backend Service namespace instead of...

  • EPSS 0.41%
  • Veröffentlicht 22.07.2026 11:21:46
  • Zuletzt bearbeitet 06.08.2026 15:42:22

Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When ReplacePathRegex is configured with a regex that captures user-controlled path se...

  • EPSS 0.21%
  • Veröffentlicht 06.07.2026 20:33:36
  • Zuletzt bearbeitet 08.07.2026 20:16:52

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not acc...

  • EPSS 0.28%
  • Veröffentlicht 06.07.2026 20:27:32
  • Zuletzt bearbeitet 08.07.2026 03:01:20

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef fi...

  • EPSS 0.23%
  • Veröffentlicht 06.07.2026 20:20:29
  • Zuletzt bearbeitet 08.07.2026 03:01:46

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service ...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 23.06.2026 19:17:07
  • Zuletzt bearbeitet 26.06.2026 16:37:18

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables Basi...

Exploit
  • EPSS 0.32%
  • Veröffentlicht 23.06.2026 19:15:38
  • Zuletzt bearbeitet 26.06.2026 16:37:51

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.06.2026 19:13:28
  • Zuletzt bearbeitet 02.09.2026 13:18:02

Traefik is an HTTP reverse proxy and load balancer. Versions prior to 3.7.3, 3.6.18, and 2.11.51 have a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS e...

Exploit
  • EPSS 0.28%
  • Veröffentlicht 23.06.2026 19:12:10
  • Zuletzt bearbeitet 02.09.2026 13:17:59

Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard...

Exploit
  • EPSS 0.87%
  • Veröffentlicht 23.06.2026 19:10:31
  • Zuletzt bearbeitet 02.09.2026 13:17:58

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and autho...