Security: traefik/traefik
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesGHSA-3g6v-2r68-prfc published
Jun 11, 2026 by emilevaugeModerate -
Traefik StripPrefix Route-Level Auth Bypass via Path NormalizationGHSA-xf64-8mw2-4gr2 published
Jun 5, 2026 by nmenginHigh -
SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypassGHSA-5r4w-85f3-pw66 published
Jun 5, 2026 by nmenginHigh -
HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hostsGHSA-9cr8-q42q-g8m7 published
Jun 5, 2026 by nmenginHigh -
Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=falseGHSA-96qj-4jj5-wcjc published
May 11, 2026 by nmenginModerate -
Traefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingGHSA-xhjw-95fp-8vgq published
Apr 24, 2026 by nmenginModerate -
Errors middleware forwards Authorization and Cookie headers to separate error page serviceGHSA-p6hg-qh38-555r published
May 4, 2026 by nmenginModerate -
BasicAuth middleware: timing side-channel vulnerabilityGHSA-6x2q-h3cr-8j2h published
Apr 24, 2026 by nmenginModerate -
Forwarded alias spoofing top pre-auth decision bypassGHSA-5m6w-wvh7-57vm published
Apr 24, 2026 by nmenginHigh -
ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authGHSA-6384-m2mw-rf54 published
Apr 24, 2026 by nmenginHigh