Security: traefik/traefik
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseGHSA-96qj-4jj5-wcjc published
May 11, 2026 by nmenginModerate -
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingGHSA-xhjw-95fp-8vgq published
Apr 24, 2026 by nmenginModerate -
Errors middleware forwards Authorization and Cookie headers to separate error page serviceGHSA-p6hg-qh38-555r published
May 4, 2026 by nmenginModerate -
BasicAuth middleware: timing side-channel vulnerabilityGHSA-6x2q-h3cr-8j2h published
Apr 24, 2026 by nmenginModerate -
Forwarded alias spoofing top pre-auth decision bypassGHSA-5m6w-wvh7-57vm published
Apr 24, 2026 by nmenginHigh -
ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authGHSA-6384-m2mw-rf54 published
Apr 24, 2026 by nmenginHigh -
StripPrefixRegex auth bypass via Path/RawPath desyncGHSA-6jwx-7vp4-9847 published
Apr 24, 2026 by nmenginHigh -
Fix CVE-2026-33186GHSA-46wh-3698-f2cx published
Mar 27, 2026 by nmenginHigh -
BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldGHSA-qr99-7898-vr7c published
Mar 27, 2026 by nmenginModerate -
Ingress Rule Injection Allows Host Restriction Bypass in TraefikGHSA-67jx-r9pv-98rj published
Mar 27, 2026 by nmenginModerate