VYPR

rpm package

opensuse/traefik&distro=openSUSE Tumbleweed

pkg:rpm/opensuse/traefik&distro=openSUSE%20Tumbleweed

Vulnerabilities (61)

  • CVE-2026-54765HigJul 6, 2026
    affected < 3.7.7-1.1fixed 3.7.7-1.1

    Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that target the same backend Service:port but configure different backendRef filters to the same child servic

  • CVE-2026-54764MedJul 6, 2026
    affected < 3.7.7-1.1fixed 3.7.7-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming req

  • CVE-2026-54763CriJul 6, 2026
    affected < 3.7.7-1.1fixed 3.7.7-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant he

  • CVE-2026-54762HigJun 23, 2026
    affected < 3.7.7-1.1fixed 3.7.7-1.1

    Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes affected routes to fail open. When an Ingress explicitly enables BasicAuth or DigestAuth through th

  • CVE-2026-54761HigJun 23, 2026
    affected < 3.7.7-1.1fixed 3.7.7-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.21 and 3.7.5, there is a high severity vulnerability in Traefik's Kubernetes Gateway provider affecting the crossProviderNamespaces allowlist. For HTTPRoute rules that declare multiple (WRR) backendRefs, Traefik eva

  • CVE-2026-53622CriJun 23, 2026
    affected < 3.7.5-1.1fixed 3.7.5-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, th

  • CVE-2026-48491CriJun 23, 2026
    affected < 3.7.5-1.1fixed 3.7.5-1.1

    Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an unauthenticated client to bypass mutual TLS enforced through wildcard router TLSOptions. When a rou

  • CVE-2026-48020CriJun 23, 2026
    affected < 3.7.5-1.1fixed 3.7.5-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an unauthenticated attacker to bypass route-level authentication and authorization. When a public router

  • CVE-2026-44774CriMay 15, 2026
    affected < 3.6.17-1.1fixed 3.6.17-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the REST provider handler, bypassing the providers.rest.insecure=false setting. The Gat

  • CVE-2026-41181MedMay 15, 2026
    affected < 3.6.16-1.1fixed 3.6.16-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information disclosure vulnerability in Traefik's errors (custom error pages) middleware. When the backend returns a response matching the configured status range, the middle

  • CVE-2026-41263LowApr 30, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a timing side-channel vulnerability in Traefik's BasicAuth middleware that allows an attacker to enumerate valid usernames through response-time differences. The variab

  • CVE-2026-41174MedApr 30, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolation enforcement. When providers.kubernetesCRD.allowCrossNamespace=false, Traefik co

  • CVE-2026-40912HigApr 30, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middleware when used in combination with ForwardAuth, BasicAuth, or DigestAuth. The mi

  • CVE-2026-39858CriApr 30, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic

  • CVE-2026-35051CriApr 30, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream

  • CVE-2026-34986HigApr 6, 2026
    affected < 3.6.15-1.1fixed 3.6.15-1.1

    Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. Prior to 4.1.4 and 3.0.5, decrypting a JSON Web Encryption (JW

  • CVE-2026-32695HigMar 27, 2026
    affected < 3.6.12-1.1fixed 3.6.12-1.1

    Traefik is an HTTP reverse proxy and load balancer. Prior to versions 3.6.11 and 3.7.0-ea.2, Traefik's Knative provider builds router rules by interpolating user-controlled values into backtick-delimited rule expressions without escaping. In live cluster validation, Knative `rule

  • CVE-2026-33186CriMar 20, 2026
    affected < 3.7.9-1.1fixed 3.7.9-1.1

    gRPC-Go is the Go language implementation of gRPC. Versions prior to 1.79.3 have an authorization bypass resulting from improper input validation of the HTTP/2 `:path` pseudo-header. The gRPC-Go server was too lenient in its routing logic, accepting requests where the `:path` omi

  • CVE-2026-32595LowMar 20, 2026
    affected < 3.6.12-1.1fixed 3.6.12-1.1

    Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 comtain BasicAuth middleware that allows username enumeration via a timing attack. When a submitted username exists, the middleware performs a bcrypt passwor

  • CVE-2026-32305MedMar 20, 2026
    affected < 3.6.12-1.1fixed 3.6.12-1.1

    Traefik is an HTTP reverse proxy and load balancer. Versions 2.11.40 and below, 3.0.0-beta1 through 3.6.11, and 3.7.0-ea.1 are vulnerable to mTLS bypass through the TLS SNI pre-sniffing logic related to fragmented ClientHello packets. When a TLS ClientHello is fragmented across m

Page 1 of 4