Where
-Infinity
0

Traefik traefikTraefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass

Risk 52
Severity
5.3
First published (updated )

Traefik traefikTraefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef

Risk 52
Severity
5.3
First published (updated )

Traefik traefikTraefik before v2.11.52 Authentication Bypass via ReplacePathRegex

Risk 65
Severity
7.8
First published (updated )

Traefik traefikTraefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

Risk 73
Severity
7.8
First published (updated )

Traefik traefikTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

Risk 55
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Traefik traefikForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

Risk 33
Severity
6.9
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a …

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerabilit…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 req…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Traefik traefikTraefik - Denial of Service via HTTP/2 Request Handling

Risk 47
Severity
8.7
First published (updated )

go/github.com/traefik/traefik/v3Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

Risk 49
Severity
5.9
First published (updated )

go/github.com/traefik/traefik/v3Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik services

Risk 48
Severity
6
First published (updated )

go/github.com/traefik/traefikTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Risk 73
Severity
7.8
First published (updated )

go/TraefikTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Risk 73
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Traefik traefikTraefik StripPrefix Route-Level Auth Bypass via Path Normalization

Risk 73
Severity
7.8
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's K…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false

Risk 82
Severity
6.4
First published (updated )

Traefik traefikTraefik: Errors middleware forwards Authorization and Cookie headers to separate error page service

Risk 33
Severity
6.9
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.…

Risk 33
Severity
7
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik: BasicAuth middleware: timing side-channel vulnerability

Risk 30
Severity
6.3
First published (updated )

Traefik traefikTraefik Kubernetes CRD allows unauthorized cross-namespace middleware binding

Risk 39
Severity
4.8
First published (updated )

Traefik traefikTraefik: StripPrefixRegex auth bypass via Path/RawPath desync

Risk 49
Severity
7.8
First published (updated )

Traefik traefikTraefik: Forwarded alias spoofing top pre-auth decision bypass

Risk 73
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Traefik traefikTraefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth

Risk 73
Severity
7.8
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik…

Risk 33
Severity
7
First published (updated )

Traefik traefikTraefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField

Risk 79
Severity
5.1
First published (updated )

Traefik traefikTraefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass

Risk 44
Severity
6.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203