Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Traefik

First CVE: Aug 21, 2018Active for: 8 yearsTotal CVEs: 53
68.9
VTI Score
TOP TARGET

Traefik is a lightweight, widely deployed reverse proxy and ingress controller used extensively in containerized and Kubernetes environments, where its request-routing and load-balancing role places it in a sensitive position within application delivery pipelines. Despite a narrow product scope—concentrated in the Traefik proxy itself and its enterprise variant—the vendor occupies a prominent position in the modern infrastructure landscape and its vulnerabilities skew toward serious outcomes, with an elevated tendency to reach critical severity. The exposure recurs through weakness classes including uncontrolled resource consumption, improper certificate validation, path traversal, and resource-allocation defects that reflect the parsing, validation, and state-management demands of a protocol-handling proxy operating at the network edge. Defenders should treat Traefik updates as high-priority for internet-exposed and Kubernetes-integrated deployments, where a compromise can affect multiple backend services and traffic flows. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
53
Total CVEs
More Total CVEs than 99% of tracked vendors
2.9
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 91% of tracked vendors
7.4
Avg CVSS Score
Higher Avg CVSS Score than 56% of tracked vendors
1.9%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Traefik over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2018
7 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (53 CVEs).

53 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2023-44487HIGH
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through
Oct 10, 20237.597YESYES
CVE-2026-39858CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's For
Apr 30, 202610.041NONO
CVE-2026-35051CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth midd
Apr 30, 202610.041NONO
CVE-2026-54763CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoof
Jul 6, 202610.040NONO
CVE-2026-48020CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an u
Jun 23, 202610.040NONO
CVE-2026-54765HIGH
Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that targ
Jul 6, 20268.536NONO
CVE-2026-53622CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthentic
Jun 23, 202610.036NONO
CVE-2026-48491CRITICAL
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an
Jun 23, 202610.036NONO
CVE-2026-44774CRITICAL
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissio
May 15, 20269.936NONO
CVE-2026-54762HIGH
Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes
Jun 23, 20268.635NONO
View all 53 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products53 CVEs
30%
47%
19%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network53 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low45 (84.9%)
High8 (15.1%)
Unknown0 (0.0%)
User Interaction
None51 (96.2%)
Unknown0 (0.0%)
Required2 (3.8%)
Privileges Required
Low12 (22.6%)
High1 (1.9%)
None40 (75.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (53 CVEs).

CISA KEV
1 CVE
1.9% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.9% of CVEs· 95th percentile
ExploitDB
1 CVE
1.9% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Traefik.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Traefik — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Traefik's Products

View all 3 CNAs →

Top CWEs