CVE Tools

Github.com/traefik/traefik

15 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Github.com/traefik/traefik, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Github.com/traefik/traefik CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Github.com/traefik/traefik CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-041
2025-051
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-021
2026-031
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 15 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical327%
  • High436%
  • Medium436%

Latest CVEs

The 15 most recently published vulnerabilities affecting Github.com/traefik/traefik.

  1. CVE-2026-29777Traefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values6.5
  2. GHSA-gv8r-9rw9-9697Traefik affected by TLS ClientAuth Bypass on HTTP/3—
  3. CVE-2025-66490Traefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules6.5
  4. CVE-2025-47952Traefik allows path traversal using url encoding9.1
  5. CVE-2025-32431Traefik has a possible vulnerability with the path matchers9.1
  6. CVE-2024-45410HTTP client can remove the X-Forwarded headers in Traefik9.8
  7. GHSA-7jmw-8259-q9jxTraefik has unexpected behavior with IPv4-mapped IPv6 addresses—
  8. GHSA-f7cq-5v43-8pwpTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop—
  9. CVE-2024-28869Possible denial of service vulnerability with Content-length header in Traefik7.5
  10. GHSA-7v4p-328v-8v5gTraefik vulnerable to HTTP/2 request causing denial of service —
  11. CVE-2021-32813Drop Headers via Malicious Connection Header4.8
  12. CVE-2020-15129Open redirect in Traefik6.1
  13. CVE-2020-9321configurationwatcher.go in Traefik 2.x before 2.1.4 and TraefikEE 2.0.0 mishandles the purging of certificate contents from providers before logging.7.5
  14. CVE-2019-12452types/types.go in Containous Traefik 1.7.x through 1.7.11, when the --api flag is used and the API is publicly reachable and exposed without sufficient access control (which is contrary to the API ...7.5
  15. CVE-2018-15598Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.7.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store