Vulnerabilidades em traefik
52 resultadosAnálise Vexday
Traefik apresenta 43 vulnerabilidades catalogadas, com 15 publicadas nos últimos 90 dias, indicando ritmo ativo de descobertas. Embora nenhuma esteja sob exploração ativa conhecida (KEV), a fraqueza dominante em traversal de diretório (CWE-22) e uma vulnerabilidade crítica requerem atenção prioritária em ambientes de produção.
CVE-2026-53622HIGHTraefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hostsEPSS 0.3%CVE-2026-48491HIGHTraefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypassEPSS 0.3%CVE-2026-29777MEDIUMTraefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesEPSS 0.3%CVE-2026-54765MEDIUMTraefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:portEPSS 0.3%CVE-2026-65601MEDIUMTraefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRefEPSS 0.3%CVE-2026-35051HIGHTraefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authEPSS 0.3%CVE-2026-41174MEDIUMTraefik Kubernetes CRD allows unauthorized cross-namespace middleware bindingEPSS 0.3%CVE-2026-54764MEDIUMForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=falseEPSS 0.2%CVE-2025-66491MEDIUMTraefik has Inverted TLS Verification Logic in its ingress-nginx ProviderEPSS 0.2%CVE-2026-54763HIGHTraefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuthEPSS 0.2%CVE-2026-65602MEDIUMTraefik before 3.6.23 IngressRouteTCP ServersTransport Namespace BypassEPSS 0.2%CVE-2026-71325MEDIUMTraefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRefEPSS 0.1%