traefik security advisories
11 threat alerts tracking vulnerabilities and security advisories that affect traefik products.
Vulnios monitors traefik CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent traefik security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2026-85594 — traefik — traefik
Traefik versions from v3.7.1 fail to enforce crossProviderNamespaces restrictions on the traefik.ingress.kubernetes.io/service.middlewares Service annotation in the Kubernetes Ingress provider. A name
criticalCVE-2026-85594Critical Vulnerability: CVE-2026-85595 — traefik — traefik
Traefik versions before v2.11.55 and versions v3.0.0 through v3.7.10 contain an authentication bypass vulnerability in the digestAuth middleware where unknown usernames receive an empty secret instead
criticalCVE-2026-85595Critical Vulnerability: CVE-2026-85596 — traefik — traefik
Traefik versions >= v3.7.0 and <= v3.7.10 contain an authentication bypass in the Kubernetes Ingress NGINX provider. The TLS option generated for an Ingress carrying the nginx.ingress.kubernetes.io/au
criticalCVE-2026-85596Critical Vulnerability: CVE-2026-85597 — traefik — traefik
Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating
criticalCVE-2026-85597Critical Vulnerability: CVE-2026-54763 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers
criticalCVE-2026-54763Critical Vulnerability: CVE-2026-48020 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attac
criticalCVE-2026-48020Critical Vulnerability: CVE-2026-48491 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated cli
criticalCVE-2026-48491Critical Vulnerability: CVE-2026-53622 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypa
criticalCVE-2026-53622Critical Vulnerability: CVE-2026-44774 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the RES
criticalCVE-2026-44774Critical Vulnerability: CVE-2026-39858 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet
criticalCVE-2026-39858Critical Vulnerability: CVE-2026-35051 — traefik — traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustFor
criticalCVE-2026-35051
Track traefik exposure across your environment
Vulnios automatically cross-references your asset inventory against new traefik CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan