Security: traefik/traefik
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication BypassGHSA-8rxv-jg7p-wvg3 published
Jul 16, 2026 by kevinpolletHigh -
Authentication Bypass via Path Traversal in ReplacePathRegex MiddlewareGHSA-cxjq-mrr5-89rv published
Jul 9, 2026 by rtribotteHigh -
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace ConfusionGHSA-qq9q-x9w4-chhj published
Jul 9, 2026 by rtribotteModerate -
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace BypassGHSA-42cj-m3vj-89wv published
Jul 9, 2026 by rtribotteModerate -
Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portGHSA-6p8f-p8j2-rqmv published
Jul 1, 2026 by mmaturModerate -
Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesGHSA-3g6v-2r68-prfc published
Jun 11, 2026 by emilevaugeModerate -
Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsGHSA-4mr2-fg2p-w63c published
Jun 19, 2026 by kevinpolletModerate -
ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falseGHSA-3q9r-p662-5j8m published
Jul 1, 2026 by mmaturModerate -
Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthGHSA-x677-9fxg-v5c5 published
Jul 1, 2026 by mmaturHigh -
Traefik StripPrefix Route-Level Auth Bypass via Path NormalizationGHSA-xf64-8mw2-4gr2 published
Jun 5, 2026 by nmenginHigh