traefik
14 known vulnerabilities in traefik, 3 critical, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-88010 CVSS 6.3 medium Traefik is an open source HTTP reverse proxy and load balancer. From 3.6.11 until 3.7.13, checkPassword in…
- CVE-2026-88012 CVSS 5.3 medium Traefik is an open source HTTP reverse proxy and load balancer. From 2.8.2 until 2.11.56 and 3.7.12, HTTP/3 entrypoints do not apply…
- CVE-2026-88011 CVSS 5.3 medium Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form…
- CVE-2026-88009 CVSS 8.8 high Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request…
- CVE-2026-88008 CVSS 7.0 high Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied…
- CVE-2026-88007 CVSS 9.1 critical Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext…
- CVE-2026-88004 CVSS 7.0 high Traefik is an open source HTTP reverse proxy and load balancer. From 3.2.0 until 3.7.13, Traefik entrypoint defenses aliasHeadersStrategy…
- CVE-2026-88879 CVSS 5.3 medium Traefik is an HTTP reverse proxy and load balancer. In Traefik v1.x, v2.x through v2.11.55, and v3.0.0 through v3.7.11, header names are…
- CVE-2026-88878 CVSS 6.9 medium Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the…
- CVE-2026-88877 CVSS 9.3 critical Traefik is a HTTP reverse proxy and load balancer. In versions >= v3.7.0 and <= v3.7.11, the Kubernetes ingress-nginx provider mishandles…
- CVE-2026-85597 CVSS 8.2 high Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated…
- CVE-2026-85596 CVSS 8.2 high Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option…
- CVE-2026-85595 CVSS 9.3 critical Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth…
- CVE-2026-85594 CVSS 7.0 high Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares…