Loading...
Skip to main content
Go Modules

github.com/traefik/traefik Security Analysis

github.com/traefik/traefik has 9 known security vulnerabilities in Go Modules. Review the table below for affected and fixed versions. Data sourced from OSV, enriched with EPSS exploit probability and CISA KEV.

9 Vulnerabilities

Low Immediate Risk

No actively exploited vulnerabilities detected. Monitor and update in your next maintenance window.

Is github.com/traefik/traefik in your project?

Check if you're affected by these 9 vulnerabilities.

9
Total
0
Critical
0
High
0
Medium
0
Low

Vulnerabilities

9 unique vulnerabilities — sorted by exploitation risk (KEV → EPSS → CVSS). Click a CVE/GHSA ID for full details.

CVE / GHSASeverityAffectedFixed In
CVE-2026-65600
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
CRITICAL
All versionsNo fix available
CVE-2026-71324
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
HIGH
All versionsNo fix available
CVE-2026-39858
Traefik: Pre-authentication decision bypass due to forwarded alias spoofing
HIGH
All versionsNo fix available
CVE-2026-35051
Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication
HIGH
All versionsNo fix available
CVE-2026-32305
Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config
HIGH
All versionsNo fix available
CVE-2026-53622
Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
HIGH
All versionsNo fix available
CVE-2025-32431
Traefik has a possible vulnerability with its path matchers
HIGH
All versionsNo fix available
CVE-2026-40912
Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync
HIGH
All versionsNo fix available
CVE-2026-44774
Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false
MEDIUM
All versionsNo fix available

About This Data

Vulnerability data for github.com/traefik/traefik is sourced from the Open Source Vulnerability (OSV) database, aggregating reports from GitHub Advisory Database, NIST NVD, and ecosystem-specific sources.

CVSS (Common Vulnerability Scoring System) scores reflect exploitability and impact. EPSS (Exploit Prediction Scoring System) scores indicate the probability of exploitation within the next 30 days. Vulnerabilities marked with are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Check Your Dependencies

Scan your project to check if you're using a vulnerable version of github.com/traefik/traefik.

Data from OSV DatabaseUpdated daily200K+ vulnerabilities indexed