Traefik is a lightweight, widely deployed reverse proxy and ingress controller used extensively in containerized and Kubernetes environments, where its request-routing and load-balancing role places it in a sensitive position within application delivery pipelines. Despite a narrow product scope—concentrated in the Traefik proxy itself and its enterprise variant—the vendor occupies a prominent position in the modern infrastructure landscape and its vulnerabilities skew toward serious outcomes, with an elevated tendency to reach critical severity. The exposure recurs through weakness classes including uncontrolled resource consumption, improper certificate validation, path traversal, and resource-allocation defects that reflect the parsing, validation, and state-management demands of a protocol-handling proxy operating at the network edge. Defenders should treat Traefik updates as high-priority for internet-exposed and Kubernetes-integrated deployments, where a compromise can affect multiple backend services and traffic flows. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Traefik over time
Signals from CVEs in this vendor scope (53 CVEs).
53 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-44487HIGH The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through | Oct 10, 2023 | 7.5 | 97 | YES | YES |
CVE-2026-39858CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's For | Apr 30, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-35051CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth midd | Apr 30, 2026 | 10.0 | 41 | NO | NO |
CVE-2026-54763CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoof | Jul 6, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-48020CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.48, 3.6.19, and 3.7.3, there is a high severity vulnerability in Traefik's StripPrefix middleware that allows an u | Jun 23, 2026 | 10.0 | 40 | NO | NO |
CVE-2026-54765HIGH Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gateway API provider may resolve two accepted HTTPRoutes that targ | Jul 6, 2026 | 8.5 | 36 | NO | NO |
CVE-2026-53622CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthentic | Jun 23, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-48491CRITICAL Traefik is an HTTP reverse proxy and load balancer. From 3.7.0 until 3.7.3, there is a high severity vulnerability in Traefik's domain-fronting protection (SNICheck) that allows an | Jun 23, 2026 | 10.0 | 36 | NO | NO |
CVE-2026-44774CRITICAL Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissio | May 15, 2026 | 9.9 | 36 | NO | NO |
CVE-2026-54762HIGH Traefik is an HTTP reverse proxy and load balancer. From 3.7.0-ea.1 until 3.7.5, there is a medium severity vulnerability in Traefik's Kubernetes Ingress NGINX provider that causes | Jun 23, 2026 | 8.6 | 35 | NO | NO |
Signals from CVEs in this vendor scope (53 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Traefik.
Media articles that mention a CVE ID that affects a product developed by Traefik — matched by CVE ID, not by vendor name.