traefik
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 42 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 21, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
Traefik: Errors middleware forwards Authorization and Cookie headers to separate error page service
Traefik: BasicAuth middleware: timing side-channel vulnerability
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding
Traefik: StripPrefixRegex auth bypass via Path/RawPath desync
Traefik: Forwarded alias spoofing top pre-auth decision bypass
Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth
Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField
Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass
Traefik: BasicAuth Middleware Timing Attack Allows Username Enumeration
Monitor traefik in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.