vendor

traefik

19 thingsrelated by NVD

Its products

traefik 19

Being told

Watch: its feed Ask more of it

The feed says each thing that enters, leaves or changes; a reader adds its address, /zetlyn/trackers/cve/things.atom?q=…, to theirs.

Every thing

github.com/traefik/traefik: Traefik: Identity spoofing via HTTP header alias
CVE-2026-88879
Severity critical
github.com/traefik/traefik: Traefik: Denial of Service via HTTP/3 timeout bypass
CVE-2026-88878
Severity high
github.com/traefik/traefik: Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
CVE-2026-88877
Severity critical
traefik: Traefik: Denial of Service via slow HTTP/3 request bodies
CVE-2026-88012
Severity high
github.com/traefik/traefik: Traefik: Identity spoofing via dot-form header alias
CVE-2026-88011
Severity critical
github.com/traefik/traefik: Traefik: Authorization bypass and access-log evasion via crafted HTTP/1 request
CVE-2026-88009
Severity high
github.com/traefik/traefik: Traefik: Incorrect authorization due to HTTP/2 protocol confusion
CVE-2026-88008
Severity critical
github.com/traefik/traefik: Traefik HTTP/3 Backend NTLM Connection Reuse
CVE-2026-88007
Severity critical
github.com/traefik/traefik: Traefik: Security bypass and identity spoofing via unsanitized request trailers
CVE-2026-88004
Severity high
github.com/traefik/traefik: Traefik: Authentication bypass via TLS option conflict
CVE-2026-85597
Severity critical
github.com/traefik/traefik: Traefik: Authentication bypass due to TLS configuration conflict
CVE-2026-85596
Severity critical
github.com/traefik/traefik: Traefik before v2.11.55 and v3.0.0 through v3.7.10 Authentication Bypass via digestAuth
CVE-2026-85595
Severity critical
github.com/traefik/traefik: Traefik: Information disclosure via crossProviderNamespaces bypass in Kubernetes Ingress provider
CVE-2026-85594
Severity critical
github.com/traefik/traefik: Traefik: Cross-namespace backend hijacking due to Gateway API identity collision
CVE-2026-71327
Severity high
github.com/traefik/traefik: Traefik: Authenticated identity spoofing via BasicAuth key collision
CVE-2026-71326
Severity low
github.com/traefik/traefik: Traefik: Namespace isolation bypass via TraefikService backendRef
CVE-2026-71325
Severity high
github.com/traefik/traefik: Traefik: Information disclosure via response poisoning in shared backend pool
CVE-2026-71324
Severity critical
github.com/traefik/traefik: Traefik: Authentication bypass via path traversal in RewriteTarget middleware
CVE-2026-67309
Severity critical
github.com/traefik/traefik: net/http2: Traefik: Denial of Service via HTTP/2 Rapid Reset technique
CVE-2023-54365
Severity high