CVE-2023-54365
- EPSS 0.57%
- Veröffentlicht 23.06.2026 12:12:51
- Zuletzt bearbeitet 26.09.2026 23:10:00
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote ...
CVE-2026-44774
- EPSS 0.47%
- Veröffentlicht 15.05.2026 16:30:43
- Zuletzt bearbeitet 15.07.2026 02:22:01
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.i...
CVE-2026-41181
- EPSS 0.45%
- Veröffentlicht 15.05.2026 16:27:14
- Zuletzt bearbeitet 19.05.2026 12:24:19
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information disclosure vulnerability in Traefik's errors (custom error pages) middleware. When the backend returns a response matching the confi...
CVE-2026-41263
- EPSS 0.37%
- Veröffentlicht 30.04.2026 20:39:49
- Zuletzt bearbeitet 01.05.2026 17:37:12
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through respons...
CVE-2026-40912
- EPSS 0.77%
- Veröffentlicht 30.04.2026 20:38:21
- Zuletzt bearbeitet 15.07.2026 02:21:10
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, Ba...
- EPSS 0.48%
- Veröffentlicht 30.04.2026 20:26:26
- Zuletzt bearbeitet 15.07.2026 02:20:53
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwar...
- EPSS 0.27%
- Veröffentlicht 30.04.2026 20:26:06
- Zuletzt bearbeitet 15.07.2026 02:20:40
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is depl...
CVE-2026-41174
- EPSS 0.25%
- Veröffentlicht 30.04.2026 20:20:29
- Zuletzt bearbeitet 01.05.2026 17:39:35
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCr...
CVE-2026-33433
- EPSS 0.47%
- Veröffentlicht 27.03.2026 13:49:08
- Zuletzt bearbeitet 15.07.2026 02:20:13
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker ca...
CVE-2026-32695
- EPSS 0.46%
- Veröffentlicht 27.03.2026 13:47:03
- Zuletzt bearbeitet 15.07.2026 02:20:00
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live clu...