📦 Traefik

by Traefik

🔍 What is Traefik?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54386

CRITICAL CVSS 9.8 Aug 2, 2025

A path traversal vulnerability in Traefik's WASM plugin installation mechanism allows attackers to overwrite arbitrary system files by uploading malicious ZIP archives containing directory traversal s...

CVE-2025-47952

CRITICAL CVSS 9.1 May 30, 2025

This vulnerability in Traefik allows attackers to bypass router path matching rules by using URL-encoded strings in request paths. This could enable access to backend services that should be protected...

CVE-2025-32431

CRITICAL CVSS 9.1 Apr 21, 2025

Traefik reverse proxy versions before 2.11.24, 3.3.6, and 3.4.0-rc2 contain a path traversal vulnerability in path-based routing matchers. Attackers can bypass middleware security controls and access ...

CVE-2026-29054

HIGH CVSS 7.5 Mar 5, 2026

This vulnerability allows remote unauthenticated attackers to bypass Traefik's protection mechanisms and remove critical X-Forwarded headers that identify client information. Attackers can manipulate ...

CVE-2026-26999

HIGH CVSS 7.5 Mar 5, 2026

This vulnerability allows remote unauthenticated attackers to cause denial of service in Traefik by exploiting a TLS handshake flaw. Attackers can send incomplete TLS records to stall connections inde...

CVE-2026-25949

HIGH CVSS 7.5 Feb 12, 2026

This vulnerability allows unauthenticated attackers to cause denial of service in Traefik reverse proxy by exploiting a STARTTLS timeout bypass. Attackers can send a specific 8-byte Postgres SSLReques...

CVE-2024-39321

HIGH CVSS 7.5 Jul 5, 2024

This vulnerability allows attackers to bypass IP allow-lists in Traefik reverse proxy by sending HTTP/3 early data requests with spoofed IP addresses during QUIC 0-RTT handshakes. This affects all Tra...

CVE-2023-47633

HIGH CVSS 7.5 Dec 4, 2023

Traefik's Docker integration creates an automatic route where Traefik serves as its own backend, causing 100% CPU consumption in a denial-of-service condition. This affects all Traefik deployments usi...

CVE-2023-44487

HIGH CVSS 7.5 Oct 10, 2023

CVE-2023-44487 is an HTTP/2 protocol vulnerability that allows attackers to cause denial of service by rapidly resetting streams, consuming server resources. This affects any system using HTTP/2, incl...

CVE-2023-29013

HIGH CVSS 7.5 Apr 14, 2023

A memory allocation vulnerability in Go's HTTP header parsing affects Traefik reverse proxy. Attackers can send specially crafted HTTP headers to cause excessive memory consumption, leading to denial ...

CVE-2022-23632

HIGH CVSS 7.4 Feb 17, 2022

Traefik versions before 2.6.1 incorrectly handle TLS configuration when requests use fully qualified domain names (FQDNs) in the Host header, potentially causing the wrong TLS certificate to be used. ...

CVE-2020-9321

HIGH CVSS 7.5 Mar 16, 2020

Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 fail to properly purge certificate contents before logging, potentially exposing sensitive TLS certificate data in log files. This affects administrators u...

CVE-2026-26998

MEDIUM CVSS 4.4 Mar 5, 2026

Traefik reverse proxy versions before 2.11.38 and 3.6.9 have a memory exhaustion vulnerability in the ForwardAuth middleware. When configured with ForwardAuth, Traefik reads authentication server resp...

CVE-2026-22045

MEDIUM CVSS 5.9 Jan 15, 2026

This vulnerability allows unauthenticated attackers to cause denial of service in Traefik reverse proxy by exploiting the ACME TLS-ALPN challenge mechanism. Attackers can open numerous connections and...

CVE-2025-66490

MEDIUM CVSS 6.5 Dec 9, 2025

Traefik reverse proxy versions prior to 2.11.32 and 3.6.3 have a path normalization bypass vulnerability. Attackers can use URL-encoded characters to bypass security middleware and access restricted b...

CVE-2025-66491

MEDIUM CVSS 5.9 Dec 9, 2025

Traefik versions 3.5.0 through 3.6.2 have inverted TLS verification logic in the nginx.ingress.kubernetes.io/proxy-ssl-verify annotation. Setting the annotation to 'on' (intending to enable backend TL...

CVE-2024-52003

MEDIUM CVSS 6.1 Nov 29, 2024

This vulnerability in Traefik allows attackers to manipulate the X-Forwarded-Prefix header from untrusted sources, potentially enabling URL redirection attacks. All users running vulnerable versions o...