Medium severity6.1NVD Advisory· Published Nov 29, 2024· Updated Jun 17, 2026
CVE-2024-52003
CVE-2024-52003
Description
Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/traefik/traefik/v2Go | < 2.11.14 | 2.11.14 |
github.com/traefik/traefik/v3Go | < 3.2.1 | 3.2.1 |
Affected products
6- osv-coords4 versionspkg:apk/chainguard/traefik-2.11pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Tumbleweedpkg:golang/github.com/traefik/traefik/v2pkg:golang/github.com/traefik/traefik/v3
< 2.11.14-r0+ 3 more
- (no CPE)range: < 2.11.14-r0
- (no CPE)range: < 0.0.20241209T183251-1.1
- (no CPE)range: < 2.11.14
- (no CPE)range: < 3.2.1
Patches
Vulnerability mechanics
References
6- github.com/traefik/traefik/pull/11253nvdPatchWEB
- github.com/traefik/traefik/security/advisories/GHSA-h924-8g65-j9wgnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-h924-8g65-j9wgghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-52003ghsaADVISORY
- github.com/traefik/traefik/releases/tag/v2.11.14nvdRelease NotesWEB
- github.com/traefik/traefik/releases/tag/v3.2.1nvdRelease NotesWEB
News mentions
0No linked articles in our index yet.