Security: traefik/traefik
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Gateway API route identity collision allows cross-namespace backend hijackingGHSA-fgjj-px3w-67xx published
Aug 3, 2026 by rtribotteHigh -
BasicAuth singleflight key collision allows authenticated identity spoofingGHSA-6765-c87h-8mrf published
Aug 3, 2026 by rtribotteLow -
`allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRefGHSA-62fc-8686-hfmq published
Aug 3, 2026 by rtribotteModerate -
Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolGHSA-3ccp-42pg-hgv6 published
Jul 27, 2026 by rtribotteHigh -
Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication BypassGHSA-8rxv-jg7p-wvg3 published
Jul 16, 2026 by kevinpolletHigh -
Authentication Bypass via Path Traversal in ReplacePathRegex MiddlewareGHSA-cxjq-mrr5-89rv published
Jul 9, 2026 by rtribotteHigh -
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace ConfusionGHSA-qq9q-x9w4-chhj published
Jul 9, 2026 by rtribotteModerate -
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace BypassGHSA-42cj-m3vj-89wv published
Jul 9, 2026 by rtribotteModerate -
Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portGHSA-6p8f-p8j2-rqmv published
Jul 1, 2026 by mmaturModerate -
Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesGHSA-3g6v-2r68-prfc published
Jun 11, 2026 by emilevaugeModerate