pkg:Go/github.com/traefik/traefik/v3
共 51 筆 CVECRITICAL2HIGH15MEDIUM11LOW1
✅ 檢查你的版本
所有已知漏洞
- CRITICAL10.0CVE-2026-39858Traefik: Pre-authentication decision bypass due to forwarded alias spoofing>= 3.7.0-ea.1, < 3.7.0-rc.2
- CRITICAL10.0CVE-2026-35051Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication>= 3.7.0-ea.1, < 3.7.0-rc.2
- HIGH8.2CVE-2026-40912Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync>= 3.7.0-ea.1, < 3.7.0-rc.2
- HIGH7.5CVE-2026-29054traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)>= 3.1.3, < 3.6.9
- HIGH7.5CVE-2026-29054traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`)>= 3.1.3, < 3.6.9
- HIGH7.5CVE-2026-26999Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)from 0, < 3.6.9
- HIGH7.5CVE-2026-26999Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS)from 0, < 3.6.9
- from 0, < 3.6.8
- from 0, < 3.6.8
- >= 3.0.0-beta3, < 3.1.3
- >= 3.0.0-beta3, < 3.1.3
- HIGH7.5CVE-2024-39321Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakes in github.com/traefik/traefik>= 3.0.0-beta3, < 3.0.4
- HIGH7.5CVE-2024-39321Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakes in github.com/traefik/traefik>= 3.0.0-beta3, < 3.0.4, >= 3.1.0-rc1, < 3.1.0-rc3
- >= 3.0.0-beta3, < 3.0.0-rc5
- >= 3.0.0-beta3, < 3.0.0-rc5
- from 0, < 3.0.0-beta5
- from 0, < 3.0.0-beta5
- MEDIUM6.5CVE-2023-47106Traefik incorrectly processes fragment in the URL, leads to Authorization Bypassfrom 0, < 3.0.0-beta5
- MEDIUM6.5CVE-2023-47106Traefik incorrectly processes fragment in the URL, leads to Authorization Bypassfrom 0, < 3.0.0-beta5
- MEDIUM6.4CVE-2026-41174Traefik Kubernetes CRD allows unauthorized cross-namespace middleware binding>= 3.7.0-ea.1, < 3.7.0-rc.2
- MEDIUM5.9CVE-2026-22045Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallfrom 0, < 3.6.7
- MEDIUM5.9CVE-2026-22045Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stallfrom 0, < 3.6.7
- >= 3.5.0, < 3.6.3
- >= 3.5.0, < 3.6.3
- from 0, < 3.0.0-beta5
- from 0, < 3.0.0-beta5
- MEDIUM4.4CVE-2026-26998Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOSfrom 0, < 3.6.9
- MEDIUM4.4CVE-2026-26998Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOSfrom 0, < 3.6.9
- LOW3.7CVE-2026-41263Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware>= 3.7.0-ea.1, < 3.7.0-rc.2
- —CVE-2026-44774Traefik: Gateway API TraefikService backend accepts rest@internal, allowing unauthorized exposure of the REST provider despite providers.rest.insecure=false>= 3.7.0, < 3.7.1
- —CVE-2026-41181Traefik's errors middleware forwards Authorization and Cookie headers to separate error page servicefrom 0, < 3.6.15
- —CVE-2026-33433Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField>= 3.0.0-beta1, < 3.6.12
- —CVE-2026-33433Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField>= 3.0.0-beta1, < 3.6.12, >= 3.7.0-ea.1, < 3.7.0-ea.3
- from 0, < 3.6.11, >= 3.7.0-ea.1, < 3.7.0-ea.2
- from 0, < 3.6.11
- from 0, < 3.6.11, >= 3.7.0-ea.1, < 3.7.0-ea.2
- from 0, < 3.6.11
- —CVE-2026-32305Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config in github.com/traefik/traefik>= 3.7.0-ea.1, < 3.7.0-ea.2
- —CVE-2026-32305Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config in github.com/traefik/traefikfrom 0, < 3.6.11, >= 3.7.0-ea.1, < 3.7.0-ea.2
- —CVE-2026-29777Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesfrom 0, < 3.6.10
- —CVE-2026-29777Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesfrom 0, < 3.6.10
- —CVE-2025-66490Path Normalization Bypass in Traefik Router + Middleware Rules in github.com/traefik/traefikfrom 0, < 3.6.3
- —CVE-2025-66490Path Normalization Bypass in Traefik Router + Middleware Rules in github.com/traefik/traefikfrom 0, < 3.6.3
- —CVE-2025-54386Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Executionfrom 0, < 3.4.5, >= 3.5.0-rc1, < 3.5.0
- —CVE-2025-54386Traefik Client Plugin's Path Traversal Vulnerability Allows Arbitrary File Overwrite and Remote Code Executionfrom 0, < 3.4.5
- from 0, < 3.4.1
- from 0, < 3.4.1
- from 0, < 3.3.6
- from 0, < 3.3.6, >= 3.4.0-rc1, < 3.4.0-rc2
- —CVE-2024-52003Traefik's X-Forwarded-Prefix Header still allows for Open Redirect in github.com/traefik/traefikfrom 0, < 3.2.1
- —CVE-2024-52003Traefik's X-Forwarded-Prefix Header still allows for Open Redirect in github.com/traefik/traefikfrom 0, < 3.2.1