These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2026-88012 debrief based on CVE Program and NVD records. Traefik 2.8.2-2.11.55 and 3.7.11 and earlier do not apply entryPoints..transport.respondingTimeouts.readTimeout for HTTP/3 entrypoints, allowing slow request body attacks that can exhaust backend connections. This issue is fixed in 2.11.56 and 3.7.12. Affected Traefik deployments using HTTP/3 entrypoints should assess exposure, verify version up [truncated]
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability allowing client-supplied dot-form headers to survive ForwardAuth replacement and underscoreHeadersStrategy. This can lead to identity spoofing for headers managed by Traefik. The issue affects versions prior to 2.11.56 and from 3.0.0 to 3.7.12. Mitigations are available in versions 2.11.56 and 3.7.12.
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability that allows for cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. This issue arises from Traefik's handling of rootless HTTP/1 request targets, which can lead to security risks when the backend interprets the opaque target as a path. The vulnerability is fixed in Traefik versions 2.11.57 and 3.7.13.
CVE-2026-88008 debrief based on the supplied source corpus. The CVE record was published on 2026-09-10T15:17:56.433Z and has not been modified since then. Traefik, an open-source HTTP reverse proxy and load balancer, has a high-severity vulnerability allowing unauthenticated requests to reach protected paths. This issue arises when a client-supplied Connection header requesting Upgrade, the Upgrade: h2c t [truncated]
CVE-2026-88007 debrief based on the supplied source corpus. The CVE record was published on 2026-09-10T15:17:56.183Z and has not been modified since then. The NVD entry is currently Analyzed. Traefik users, especially those with HTTP/3 enabled and connection-bound NTLM or Negotiate authentication, and backend keep-alive enabled, should assess exposure and prioritize verification. This vulnerability allows [truncated]
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability in versions 3.2.0 through 3.7.12. An unauthenticated client can submit an aliasing or trusted header name in an HTTP/1.1 chunked trailer or an HTTP/2 trailer, potentially spoofing identity or forwarded routing data. This issue is fixed in version 3.7.13. The vulnerability allows attackers to bypass security controls, potenti [truncated]
Traefik, an HTTP reverse proxy and load balancer, has a vulnerability in versions 1.x, 2.x through 2.11.55, and 3.0.0 through 3.7.11. The issue arises from the canonicalization of header names only on dashes, allowing a client to smuggle a dot-form alias of a header that Traefik manages past the middleware managing it. This can cause a backend to read the client-supplied value instead of the identity Trae [truncated]
Traefik, an HTTP reverse proxy and load balancer, has a vulnerability in versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11. The entryPoints.<name>.transport.respondingTimeouts settings, specifically readTimeout, are not applied to the HTTP/3 request path. This allows an unauthenticated remote client to hold a request open indefinitely, potentially causing denial of service by exhaust [truncated]
CVE-2026-88877 debrief based on the supplied source corpus. The CVE record was published on 2026-09-10T14:17:16.023Z and has not been modified since then. The NVD entry is currently Analyzed. This vulnerability affects Traefik instances with specific Kubernetes ingress-nginx configurations, potentially allowing authentication bypass and removal of protective middleware. Defenders should assess exposure an [truncated]
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability in its Kubernetes Gateway API provider. The issue allows colliding routes to overwrite another namespace's backend due to the way router and service identities are built. This problem affects Traefik versions from 3.0.0 to 3.6.25 and 3.7.10. The vulnerability is addressed in versions 3.6.25 and 3.7.10.
Traefik, an open-source HTTP reverse proxy and load balancer, had a vulnerability in its BasicAuth middleware. From versions 3.6.11 to 3.6.25 and 3.7.10, the middleware deduplicated concurrent password checks using a singleflight key built from the concatenation of password and secret. This allowed an attacker with valid credentials and the stored hash to authenticate as an unconfigured username when the [truncated]
CVE-2026-71325 debrief based on the supplied source corpus. The CVE record was published on 2026-08-06T22:18:29.490Z and has not been modified since then. This vulnerability in Traefik, an open-source edge router, allows cross-namespace @kubernetescrd references prior to versions 2.11.54, 3.6.25, and 3.7.10, potentially defeating namespace isolation. Defenders managing Traefik deployments, especially thos [truncated]
The CVE-2026-67309 record describes a path traversal vulnerability in Traefik versions >= v3.7.0 and <= v3.7.7. This issue is exploitable through the RewriteTarget middleware in the Kubernetes Ingress NGINX provider. A crafted request can bypass authentication mechanisms and access protected endpoints. The vulnerability is fixed in v3.7.8. Traefik users should prioritize patching to prevent potential auth [truncated]
Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references. A low-privileged Kubernetes user in a namespace not listed in crossProviderNamespaces can set serversTransport: foo@file on an IngressRouteTCP service, causing Traefik to accept the forbidden cross-provider reference and use a file-provider TCP [truncated]
A namespace confusion vulnerability was found in Traefik versions 3.7.0 through 3.7.6. The issue occurs when resolving HTTPRoute.spec.rules[].backendRefs[].filters[].extensionRef, where Traefik used the backend Service namespace instead of the HTTPRoute namespace. This allows a low-privileged route author holding a ReferenceGrant for a cross-namespace Service to bind a Traefik Middleware from the backend [truncated]
CVE-2026-65600 is an authentication bypass vulnerability in Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6. The vulnerability exists in the ReplacePathRegex middleware when configured with a regex that captures user-controlled path segments without a mandatory path separator. This allows an unauthenticated remote attacker to send a crafted request to bypass authentication midd [truncated]
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child service and apply only one route's filter set to all requests reaching that backend. In Gateway deployments where backendRef filters s [truncated]
The Traefik ForwardAuth middleware is vulnerable to an authorization bypass. An unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection, causing Traefik to forward X-Forwarded-Port: 443 to the authentication service. This issue is fixed in Traefik versions v2.11.51, v3.6.22, and v3.7.6. Affected product deployments should be reviewed for exposure.
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an [truncated]
A medium-severity vulnerability was found in Traefik's Kubernetes Ingress NGINX provider from versions 3.7.0-ea.1 until 3.7.4. This issue causes affected routes to fail open when an Ingress explicitly enables BasicAuth or DigestAuth but the referenced auth Secret cannot be resolved or parsed. As a result, Traefik logs the resolution error, skips installing the authentication middleware, and still emits a [truncated]
Traefik, an HTTP reverse proxy and load balancer, has a critical vulnerability in its HTTP/3 (QUIC) TLS configuration selection. This issue allows unauthenticated clients to bypass router-specific mTLS enforcement. The vulnerability arises because the TLS handshake selects the applicable TLS configuration through an exact, case-sensitive lookup on the SNI (Server Name Indication) value. This lookup fails [truncated]
Traefik, an HTTP reverse proxy and load balancer, has a high-severity vulnerability in its StripPrefix middleware. This vulnerability allows an unauthenticated attacker to bypass route-level authentication and authorization. The issue arises when a public router matches on a PathPrefix rule and applies the StripPrefix middleware. A request path containing .. or its percent-encoded form %2e%2e can match th [truncated]
A medium-severity vulnerability in Traefik's Kubernetes Gateway API provider allows HTTPRoute creation permissions to be abused for unauthorized dynamic configuration access. The flaw permits routing to rest@internal despite providers.rest.insecure=false, enabling live reconfiguration of routers and services in shared Gateway deployments.
Traefik's errors middleware inadvertently forwards complete request headers—including sensitive authentication material—to external error page services, contrary to documentation stating only Host is forwarded by default. This information disclosure occurs when backends return responses matching configured status ranges, exposing credentials across unintended service boundaries. The vulnerability affects [truncated]
CVE-2026-33433 is a medium-severity vulnerability in Traefik, an HTTP reverse proxy and load balancer. An authenticated attacker can inject their own canonical version of a non-canonical HTTP header to impersonate any identity to the backend. The vulnerability exists because Traefik writes non-canonical header names, allowing an attacker to override them with their own canonical version. This issue affect [truncated]
Traefik, an HTTP reverse proxy and load balancer, had a vulnerability prior to versions 3.6.11 and 3.7.0-ea.2. The issue lies in the Knative provider, which builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without proper escaping. This could be exploited in live cluster validation, particularly with `rules[].hosts[]` and `headers[].exact`, allowing for h [truncated]
CVE-2026-29054 is a high-severity vulnerability in Traefik, an HTTP reverse proxy and load balancer. The issue affects versions 2.11.9 to 2.11.37 and 3.1.3 to 3.6.8. It involves a problem with managing the Connection header and X-Forwarded headers, allowing a remote unauthenticated client to bypass protections and trigger the removal of Traefik-managed forwarded identity headers. The vulnerability has bee [truncated]
CVE-2026-26999 is a high-severity vulnerability in Traefik, an HTTP reverse proxy and load balancer. The vulnerability allows an attacker to cause a denial of service by sending an incomplete TLS record, which can stall the TLS handshake indefinitely, leading to a resource exhaustion. This issue has been patched in versions 2.11.38 and 3.6.9. Traefik's management of TLS handshakes on TCP routers is vulner [truncated]
CVE-2026-25949 is a high-severity vulnerability in Traefik, an HTTP reverse proxy and load balancer. An unauthenticated client can exploit this vulnerability by sending an 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in Traefik version 3.6.8. The Common Vulnerability Scoring Sys [truncated]