Known vulnerabilities in Traefik

Vendor: Containous
Software: Traefik
Software CPE: cpe:2.3:a:containous:traefik:*:*:*:*:*:*:*:*
Total vulnerabilities: 63
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Traefik Traefik is affected by 63 known vulnerabilities: 13 high, 33 medium, 17 low Critical High Medium Low

Vulnerabilities (63)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137268 - Incorrect Authorization
CWE-863 Low
No
No
3.6.23, 3.7.7 09.07.2026 SB2026070936
#VU137267 - Incorrect Authorization
CWE-863 Low
No
No
3.7.7 09.07.2026 SB2026070936
#VU137266 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CWE-22 Medium
No
No
2.11.52, 3.6.23, 3.7.7 09.07.2026 SB2026070936
#VU136877 - Improper Handling of Case Sensitivity
CVE-2026-54763
CWE-178 High
No
No
2.11.51, 3.6.22, 3.7.6 03.07.2026 SB2026070352
SB2026081241
#VU136876 - Insufficient Verification of Data Authenticity
CVE-2026-54764
CWE-345 Medium
No
No
2.11.51, 3.6.22, 3.7.6 03.07.2026 SB2026070352
#VU136875 - Incorrect Authorization
CVE-2026-54765
CWE-863 Low
No
No
3.7.6 03.07.2026 SB2026070352
#VU136874 - Not Failing Securely (\'Failing Open\')
CVE-2026-54762
CWE-636 Medium
No
No
3.7.5 03.07.2026 SB2026070351
#VU136873 - Improper Access Control
CVE-2026-54761
CWE-284 Low
No
No
3.6.21, 3.7.5 03.07.2026 SB2026070351
#VU136872 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-53622
CWE-288 High
No
No
3.6.18, 3.7.3 03.07.2026 SB2026070350
#VU136871 - Authentication Bypass Using an Alternate Path or Channel
CVE-2026-48491
CWE-288 High
No
No
3.7.3 03.07.2026 SB2026070350
#VU136870 - Incorrect Authorization
CVE-2026-48020
CWE-863 High
No
No
2.11.48, 3.6.19, 3.7.3 03.07.2026 SB2026070350
#VU131172 - Improper Access Control
CVE-2026-44774
CWE-284 Medium
No
No
2.11.46, 3.6.17, 3.7.1 12.05.2026 SB2026051269
#VU129679 - Insertion of Sensitive Information Into Sent Data
CVE-2026-41181
CWE-201 Medium
No
No
2.11.44, 3.6.15, 3.7.0 rc.3 05.05.2026 SB2026050536
#VU129678 - Use of Incorrectly-Resolved Name or Reference
CVE-2026-40912
CWE-706 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129677 - Insufficient Verification of Data Authenticity
CVE-2026-35051
CWE-345 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129676 - Authentication Bypass by Spoofing
CVE-2026-39858
CWE-290 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129675 - Information Exposure Through Timing Discrepancy
CVE-2026-41263
CWE-208 Low
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129674 - Improper Access Control
CVE-2026-41174
CWE-284 Low
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129671 - Authentication Bypass by Spoofing
CVE-2026-33433
CWE-290 Low
No
No
2.11.42, 3.6.12 05.05.2026 SB2026050534
#VU129670 - Information Exposure Through Timing Discrepancy
CVE-2026-32595
CWE-208 Low
No
No
2.11.41, 3.6.11 05.05.2026 SB2026050533


Showing elements 1 - 20 out of 63