{"schema_version":1,"title":"Traefik Labs Traefik Proxy vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 26 vulnerabilities in Traefik Labs Traefik Proxy: 0 in the last 7 days and 12 in the last 90 days, 2 of them critical and 0 exploited in the wild. The most recent, CVE-2026-67309, was published on 6 August 2026.","url":"https://junglewise.ai/threats/technologies/traefik-proxy","json_url":"https://junglewise.ai/threats/technologies/traefik-proxy.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/traefik-proxy","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":15,"all_time":26,"critical":2,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":12,"last_365_days":26},"latest":[{"cve":"CVE-2026-67309","cvss":4,"epss":0.0066,"slug":"cve-2026-67309-traefik-auth-bypass-via-path-traversal-in-kubernetes-ingress","title":"Traefik auth bypass via path traversal in Kubernetes Ingress NGINX provider","severity":"high","exploited":false,"published_at":"2026-08-06T16:45:28+00:00","url":"https://junglewise.ai/threats/cve-2026-67309-traefik-auth-bypass-via-path-traversal-in-kubernetes-ingress"},{"cve":"CVE-2026-71325","cvss":4,"epss":0.0016,"slug":"cve-2026-71325-traefik-namespace-isolation-bypass-in-kubernetes-crd","title":"Traefik namespace isolation bypass in Kubernetes CRD TraefikService","severity":"medium","exploited":false,"published_at":"2026-08-06T16:38:37+00:00","url":"https://junglewise.ai/threats/cve-2026-71325-traefik-namespace-isolation-bypass-in-kubernetes-crd"},{"cve":"CVE-2026-71327","cvss":8.2,"epss":0.0048,"slug":"cve-2026-71327-traefik-proxy-cross-namespace-route-hijacking-via-identity","title":"Traefik Proxy cross-namespace route hijacking via identity collision","severity":"high","exploited":false,"published_at":"2026-08-06T16:38:18+00:00","url":"https://junglewise.ai/threats/cve-2026-71327-traefik-proxy-cross-namespace-route-hijacking-via-identity"},{"cve":"CVE-2026-71326","cvss":4,"epss":0.0034,"slug":"cve-2026-71326-traefik-basicauth-identity-spoofing-via-singleflight-key","title":"Traefik BasicAuth identity spoofing via singleflight key collision","severity":"medium","exploited":false,"published_at":"2026-08-06T16:34:38+00:00","url":"https://junglewise.ai/threats/cve-2026-71326-traefik-basicauth-identity-spoofing-via-singleflight-key"},{"cve":"CVE-2026-71324","cvss":4,"epss":0.0069,"slug":"cve-2026-71324-traefik-response-poisoning-via-proxied-connect-in-shared","title":"Traefik response poisoning via proxied CONNECT in shared connection pool","severity":"high","exploited":false,"published_at":"2026-08-06T15:56:40+00:00","url":"https://junglewise.ai/threats/cve-2026-71324-traefik-response-poisoning-via-proxied-connect-in-shared"},{"cvss":7.8,"slug":"traefik-path-traversal-in-kubernetes-ingress-nginx-rewritetarget-0cb6afa7","title":"Traefik path traversal in Kubernetes Ingress NGINX RewriteTarget","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/traefik-path-traversal-in-kubernetes-ingress-nginx-rewritetarget-0cb6afa7"},{"cvss":7.8,"slug":"traefik-auth-bypass-via-path-traversal-in-replacepathregex-middleware-57873860","title":"Traefik auth bypass via path traversal in ReplacePathRegex middleware","severity":"high","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-auth-bypass-via-path-traversal-in-replacepathregex-middleware-57873860"},{"cve":"CVE-2026-65602","cvss":4,"epss":0.0033,"slug":"cve-2026-65602-traefik-authorization-bypass-in-ingressroutetcp-cross-provider","title":"Traefik authorization bypass in IngressRouteTCP cross-provider references","severity":"medium","exploited":false,"published_at":"2026-07-22T12:18:20.56+00:00","url":"https://junglewise.ai/threats/cve-2026-65602-traefik-authorization-bypass-in-ingressroutetcp-cross-provider"},{"cve":"CVE-2026-65601","cvss":4,"epss":0.0051,"slug":"cve-2026-65601-traefik-namespace-confusion-in-kubernetes-gateway-api","title":"Traefik namespace confusion in Kubernetes Gateway API extensionRef","severity":"medium","exploited":false,"published_at":"2026-07-22T12:18:20.43+00:00","url":"https://junglewise.ai/threats/cve-2026-65601-traefik-namespace-confusion-in-kubernetes-gateway-api"},{"cve":"CVE-2026-65600","cvss":9.1,"epss":0.0062,"slug":"cve-2026-65600-traefik-authentication-bypass-in-replacepathregex-middleware","title":"Traefik authentication bypass in ReplacePathRegex middleware","severity":"critical","exploited":false,"published_at":"2026-07-22T12:18:20.297+00:00","url":"https://junglewise.ai/threats/cve-2026-65600-traefik-authentication-bypass-in-replacepathregex-middleware"},{"cve":"CVE-2026-54764","cvss":5.8,"epss":0.0028,"slug":"cve-2026-54764-traefik-proxy-authorization-bypass-in-forwardauth-middleware","title":"Traefik Proxy authorization bypass in ForwardAuth middleware","severity":"medium","exploited":false,"published_at":"2026-07-06T21:16:56.93+00:00","url":"https://junglewise.ai/threats/cve-2026-54764-traefik-proxy-authorization-bypass-in-forwardauth-middleware"},{"cve":"CVE-2026-54763","cvss":4,"epss":0.0024,"slug":"cve-2026-54763-traefik-proxy-authentication-bypass-via-underscore-header","title":"Traefik Proxy authentication bypass via underscore header spoofing","severity":"high","exploited":false,"published_at":"2026-07-06T21:16:56.787+00:00","url":"https://junglewise.ai/threats/cve-2026-54763-traefik-proxy-authentication-bypass-via-underscore-header"},{"cve":"CVE-2026-54762","cvss":3.1,"epss":0.0043,"slug":"cve-2026-54762-traefik-fail-open-in-kubernetes-ingress-nginx-provider-auth","title":"Traefik fail open in Kubernetes Ingress NGINX provider auth resolution","severity":"medium","exploited":false,"published_at":"2026-06-23T20:16:49.997+00:00","url":"https://junglewise.ai/threats/cve-2026-54762-traefik-fail-open-in-kubernetes-ingress-nginx-provider-auth"},{"cve":"CVE-2026-54761","cvss":3.1,"epss":0.0037,"slug":"cve-2026-54761-traefik-authorization-bypass-in-kubernetes-gateway","title":"Traefik authorization bypass in Kubernetes Gateway crossProviderNamespaces","severity":"medium","exploited":false,"published_at":"2026-06-23T20:16:49.867+00:00","url":"https://junglewise.ai/threats/cve-2026-54761-traefik-authorization-bypass-in-kubernetes-gateway"},{"cve":"CVE-2026-53622","cvss":3.1,"epss":0.0063,"slug":"cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure","title":"Traefik mTLS bypass in HTTP/3 via exact SNI lookup failure","severity":"high","exploited":false,"published_at":"2026-06-23T20:16:48.777+00:00","url":"https://junglewise.ai/threats/cve-2026-53622-traefik-mtls-bypass-in-http-3-via-exact-sni-lookup-failure"},{"cve":"CVE-2026-48491","cvss":3.1,"epss":0.0036,"slug":"cve-2026-48491-traefik-mtls-bypass-in-snicheck-via-wildcard-domain-fronting","title":"Traefik mTLS bypass in SNICheck via wildcard domain fronting","severity":"high","exploited":false,"published_at":"2026-06-23T20:16:48.123+00:00","url":"https://junglewise.ai/threats/cve-2026-48491-traefik-mtls-bypass-in-snicheck-via-wildcard-domain-fronting"},{"cve":"CVE-2026-48020","cvss":3.1,"epss":0.0078,"slug":"cve-2026-48020-traefik-auth-bypass-via-path-normalization-in-stripprefix","title":"Traefik auth bypass via path normalization in StripPrefix middleware","severity":"high","exploited":false,"published_at":"2026-06-23T20:16:47.993+00:00","url":"https://junglewise.ai/threats/cve-2026-48020-traefik-auth-bypass-via-path-normalization-in-stripprefix"},{"cve":"CVE-2023-54365","cvss":7.5,"epss":0.0077,"slug":"cve-2023-54365-traefik-denial-of-service-via-http-2-rapid-reset","title":"Traefik denial of service via HTTP/2 Rapid Reset","severity":"high","exploited":false,"published_at":"2026-06-23T13:16:30.42+00:00","url":"https://junglewise.ai/threats/cve-2023-54365-traefik-denial-of-service-via-http-2-rapid-reset"},{"cve":"CVE-2026-44774","cvss":4,"epss":0.0055,"slug":"cve-2026-44774-traefik-unauthorized-rest-provider-exposure-in-kubernetes-gateway","title":"Traefik unauthorized REST provider exposure in Kubernetes Gateway API","severity":"medium","exploited":false,"published_at":"2026-05-15T17:16:48.21+00:00","url":"https://junglewise.ai/threats/cve-2026-44774-traefik-unauthorized-rest-provider-exposure-in-kubernetes-gateway"},{"cve":"CVE-2026-41181","cvss":4,"epss":0.005,"slug":"cve-2026-41181-traefik-information-disclosure-in-custom-error-pages-middleware","title":"Traefik information disclosure in custom error pages middleware","severity":"medium","exploited":false,"published_at":"2026-05-15T17:16:46.32+00:00","url":"https://junglewise.ai/threats/cve-2026-41181-traefik-information-disclosure-in-custom-error-pages-middleware"},{"cve":"CVE-2026-40912","cvss":8.2,"epss":0.0072,"slug":"cve-2026-40912-traefik-authentication-bypass-in-stripprefixregex-middleware","title":"Traefik authentication bypass in StripPrefixRegex middleware","severity":"high","exploited":false,"published_at":"2026-04-30T21:16:32.74+00:00","url":"https://junglewise.ai/threats/cve-2026-40912-traefik-authentication-bypass-in-stripprefixregex-middleware"},{"cve":"CVE-2026-35051","cvss":10,"epss":0.0031,"slug":"cve-2026-35051-traefik-auth-bypass-in-forwardauth-middleware-via-header-spoofing","title":"Traefik auth bypass in ForwardAuth middleware via header spoofing","severity":"critical","exploited":false,"published_at":"2026-04-30T21:16:32.047+00:00","url":"https://junglewise.ai/threats/cve-2026-35051-traefik-auth-bypass-in-forwardauth-middleware-via-header-spoofing"},{"cve":"CVE-2026-33433","cvss":8.8,"epss":0.0057,"slug":"cve-2026-33433-traefik-identity-spoofing-via-non-canonical-headerfield-in-auth","title":"Traefik identity spoofing via non-canonical headerField in Auth middleware","severity":"high","exploited":false,"published_at":"2026-03-27T15:16:54.98+00:00","url":"https://junglewise.ai/threats/cve-2026-33433-traefik-identity-spoofing-via-non-canonical-headerfield-in-auth"},{"cve":"CVE-2026-32695","cvss":7.7,"epss":0.0053,"slug":"cve-2026-32695-traefik-router-rule-injection-in-kubernetes-providers","title":"Traefik router rule injection in Kubernetes providers","severity":"high","exploited":false,"published_at":"2026-03-27T14:16:08.537+00:00","url":"https://junglewise.ai/threats/cve-2026-32695-traefik-router-rule-injection-in-kubernetes-providers"},{"cve":"CVE-2026-29054","cvss":7.5,"epss":0.0062,"slug":"cve-2026-29054-traefik-case-sensitivity-bypass-in-connection-header-allows","title":"Traefik case-sensitivity bypass in Connection header allows removal of X-Forwarded headers","severity":"high","exploited":false,"published_at":"2026-03-05T19:16:15.277+00:00","url":"https://junglewise.ai/threats/cve-2026-29054-traefik-case-sensitivity-bypass-in-connection-header-allows"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":1,"exploited":0,"vulnerabilities":4},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":5},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[],"technology":{"hub":true,"name":"Traefik Labs Traefik Proxy","slug":"traefik-proxy","vendor":{"name":"Traefik Labs","slug":"traefik-labs","url":"https://junglewise.ai/threats/vendors/traefik-labs"},"aliases":[],"category":"web-server","homepage":"https://traefik.io/traefik/","repo_url":"https://github.com/traefik/traefik","description":"Traefik Proxy is an open-source edge router and cloud-native application proxy.","url":"https://junglewise.ai/threats/technologies/traefik-proxy"},"most_severe":[{"cve":"CVE-2026-35051","cvss":10,"epss":0.0031,"slug":"cve-2026-35051-traefik-auth-bypass-in-forwardauth-middleware-via-header-spoofing","title":"Traefik auth bypass in ForwardAuth middleware via header spoofing","severity":"critical","exploited":false,"published_at":"2026-04-30T21:16:32.047+00:00","url":"https://junglewise.ai/threats/cve-2026-35051-traefik-auth-bypass-in-forwardauth-middleware-via-header-spoofing"},{"cve":"CVE-2026-65600","cvss":9.1,"epss":0.0062,"slug":"cve-2026-65600-traefik-authentication-bypass-in-replacepathregex-middleware","title":"Traefik authentication bypass in ReplacePathRegex middleware","severity":"critical","exploited":false,"published_at":"2026-07-22T12:18:20.297+00:00","url":"https://junglewise.ai/threats/cve-2026-65600-traefik-authentication-bypass-in-replacepathregex-middleware"},{"cve":"CVE-2026-33433","cvss":8.8,"epss":0.0057,"slug":"cve-2026-33433-traefik-identity-spoofing-via-non-canonical-headerfield-in-auth","title":"Traefik identity spoofing via non-canonical headerField in Auth middleware","severity":"high","exploited":false,"published_at":"2026-03-27T15:16:54.98+00:00","url":"https://junglewise.ai/threats/cve-2026-33433-traefik-identity-spoofing-via-non-canonical-headerfield-in-auth"},{"cve":"CVE-2026-40912","cvss":8.2,"epss":0.0072,"slug":"cve-2026-40912-traefik-authentication-bypass-in-stripprefixregex-middleware","title":"Traefik authentication bypass in StripPrefixRegex middleware","severity":"high","exploited":false,"published_at":"2026-04-30T21:16:32.74+00:00","url":"https://junglewise.ai/threats/cve-2026-40912-traefik-authentication-bypass-in-stripprefixregex-middleware"},{"cve":"CVE-2026-71327","cvss":8.2,"epss":0.0048,"slug":"cve-2026-71327-traefik-proxy-cross-namespace-route-hijacking-via-identity","title":"Traefik Proxy cross-namespace route hijacking via identity collision","severity":"high","exploited":false,"published_at":"2026-08-06T16:38:18+00:00","url":"https://junglewise.ai/threats/cve-2026-71327-traefik-proxy-cross-namespace-route-hijacking-via-identity"},{"cvss":7.8,"slug":"traefik-path-traversal-in-kubernetes-ingress-nginx-rewritetarget-0cb6afa7","title":"Traefik path traversal in Kubernetes Ingress NGINX RewriteTarget","severity":"high","exploited":false,"published_at":"2026-08-01T15:30:27+00:00","url":"https://junglewise.ai/threats/traefik-path-traversal-in-kubernetes-ingress-nginx-rewritetarget-0cb6afa7"},{"cvss":7.8,"slug":"traefik-auth-bypass-via-path-traversal-in-replacepathregex-middleware-57873860","title":"Traefik auth bypass via path traversal in ReplacePathRegex middleware","severity":"high","exploited":false,"published_at":"2026-07-22T12:32:18+00:00","url":"https://junglewise.ai/threats/traefik-auth-bypass-via-path-traversal-in-replacepathregex-middleware-57873860"},{"cve":"CVE-2026-32695","cvss":7.7,"epss":0.0053,"slug":"cve-2026-32695-traefik-router-rule-injection-in-kubernetes-providers","title":"Traefik router rule injection in Kubernetes providers","severity":"high","exploited":false,"published_at":"2026-03-27T14:16:08.537+00:00","url":"https://junglewise.ai/threats/cve-2026-32695-traefik-router-rule-injection-in-kubernetes-providers"},{"cve":"CVE-2026-25949","cvss":7.5,"epss":0.0082,"slug":"cve-2026-25949-traefik-proxy-denial-of-service-via-starttls-timeout-bypass","title":"Traefik Proxy Denial of Service via STARTTLS Timeout Bypass","severity":"high","exploited":false,"published_at":"2026-02-12T20:16:11.227+00:00","url":"https://junglewise.ai/threats/cve-2026-25949-traefik-proxy-denial-of-service-via-starttls-timeout-bypass"},{"cve":"CVE-2023-54365","cvss":7.5,"epss":0.0077,"slug":"cve-2023-54365-traefik-denial-of-service-via-http-2-rapid-reset","title":"Traefik denial of service via HTTP/2 Rapid Reset","severity":"high","exploited":false,"published_at":"2026-06-23T13:16:30.42+00:00","url":"https://junglewise.ai/threats/cve-2023-54365-traefik-denial-of-service-via-http-2-rapid-reset"}],"generated_at":"2026-09-26T16:07:00.132667+00:00"}