github.com/traefik/traefik/v3 vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-54763Highgithub.com/traefik/traefik/v2: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth /…CVE-2026-65600Criticalgithub.com/traefik/traefik/v2: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex MiddlewareCVE-2026-67309Highgithub.com/traefik/traefik/v3: Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication BypassCVE-2026-54765Mediumgithub.com/traefik/traefik/v3: Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portCVE-2026-71325Mediumgithub.com/traefik/traefik/v2: Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRefCVE-2026-54764Mediumgithub.com/traefik/traefik/v2: Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falseCVE-2026-71327Highgithub.com/traefik/traefik/v3: Traefik: Gateway API route identity collision allows cross-namespace backend hijackingCVE-2026-71326Lowgithub.com/traefik/traefik/v3: Traefik: BasicAuth singleflight key collision allows authenticated identity spoofingCVE-2026-71324Highgithub.com/traefik/traefik/v2: Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive poolCVE-2026-65602Mediumgithub.com/traefik/traefik/v3: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace BypassCVE-2026-54762Mediumgithub.com/traefik/traefik/v3: Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution failsCVE-2026-54761Mediumgithub.com/traefik/traefik/v3: Traefik: Kubernetes Gateway crossProviderNamespaces bypass allows HTTPRoute outside the allowlist to expose internal Traefik servicesCVE-2026-48020Highgithub.com/traefik/traefik/v2: Traefik has a StripPrefix Route-Level Auth Bypass via Path NormalizationCVE-2026-44774Mediumgithub.com/traefik/traefik/v3: Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite…CVE-2026-41181Mediumgithub.com/traefik/traefik/v2: Traefik's errors middleware forwards Authorization and Cookie headers to separate error page serviceCVE-2026-41263Mediumgithub.com/traefik/traefik/v3: Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middlewareCVE-2026-41174Mediumgithub.com/traefik/traefik/v3: Traefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingCVE-2026-40912Highgithub.com/traefik/traefik/v3: Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath DesyncCVE-2026-39858Highgithub.com/traefik/traefik/v3: Traefik: Pre-authentication decision bypass due to forwarded alias spoofingCVE-2026-35051Highgithub.com/traefik/traefik/v3: Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authenticationGHSA-46WH-3698-F2CXHighgithub.com/traefik/traefik/v2: Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)CVE-2026-33433Mediumgithub.com/traefik/traefik/v2: Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerFieldCVE-2026-32695Mediumgithub.com/traefik/traefik/v3: Traefik has Knative Ingress Rule Injection that Allows Host Restriction BypassCVE-2026-32595Mediumgithub.com/traefik/traefik: Traefik Affected by BasicAuth Middleware Timing Attack Allows Username EnumerationCVE-2026-32305Highgithub.com/traefik/traefik/v3: Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config

Stop the waste.
Protect your environment with Kodem.