Known vulnerabilities in Traefik - page 2

Vendor: Containous
Software: Traefik
Software CPE: cpe:2.3:a:containous:traefik:*:*:*:*:*:*:*:*
Total vulnerabilities: 74
Public exploits: 2
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Traefik Traefik is affected by 74 known vulnerabilities: 17 high, 37 medium, 20 low Critical High Medium Low

Vulnerabilities (74)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU144548 - Improper Authentication
CVE-2026-71326
CWE-287 Low
No
No
3.6.25, 3.7.10 21.08.2026 SB2026050535
#VU144547 - Use of Multiple Resources with Duplicate Identifier
CVE-2026-71327
CWE-694 Medium
No
No
3.6.25, 3.7.10 21.08.2026 SB2026050535
#VU131172 - Improper Access Control
CVE-2026-44774
CWE-284 Medium
No
No
2.11.46, 3.6.17, 3.7.1 12.05.2026 SB2026051269
#VU129679 - Insertion of Sensitive Information Into Sent Data
CVE-2026-41181
CWE-201 Medium
No
No
2.11.44, 3.6.15, 3.7.0 rc.3 05.05.2026 SB2026050536
#VU129678 - Use of Incorrectly-Resolved Name or Reference
CVE-2026-40912
CWE-706 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129677 - Insufficient Verification of Data Authenticity
CVE-2026-35051
CWE-345 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129676 - Authentication Bypass by Spoofing
CVE-2026-39858
CWE-290 High
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129675 - Information Exposure Through Timing Discrepancy
CVE-2026-41263
CWE-208 Low
No
No
2.11.43, 3.6.14, 3.7.0 rc.2 05.05.2026 SB2026050535
#VU129674 - Improper Access Control
CVE-2026-41174
CWE-284 Low
No
No
2.11.54, 3.6.25, 3.7.10 05.05.2026 SB2026050535
#VU129672 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-32695
CWE-74 Low
No
No
3.6.11 05.05.2026 SB2026050533
#VU129671 - Authentication Bypass by Spoofing
CVE-2026-33433
CWE-290 Low
No
No
2.11.42, 3.6.12 05.05.2026 SB2026050534
#VU129670 - Information Exposure Through Timing Discrepancy
CVE-2026-32595
CWE-208 Low
No
No
2.11.41, 3.6.11 05.05.2026 SB2026050533
#VU129669 - Authentication Bypass by Primary Weakness
CVE-2026-32305
CWE-305 High
No
No
2.11.41, 3.6.11 05.05.2026 SB2026050533
#VU129668 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CVE-2026-29777
CWE-74 Low
No
No
3.6.10 05.05.2026 SB2026050532
#VU129667 - NULL Pointer Dereference
CVE-2026-27141
CWE-476 Medium
No
No
2.11.40, 3.6.10 05.05.2026 SB2026050532
SB2026052154
SB2026070811
#VU129666 - Improper Handling of Case Sensitivity
CVE-2026-29054
CWE-178 Medium
No
No
2.11.38, 3.6.9 05.05.2026 SB2026050531
#VU129665 - Resource exhaustion
CVE-2026-26999
CWE-400 Medium
No
No
2.11.38, 3.6.9 05.05.2026 SB2026050531
#VU129664 - Allocation of Resources Without Limits or Throttling
CVE-2026-26998
CWE-770 Low
No
No
2.11.38, 3.6.9 05.05.2026 SB2026050531
#VU129663 - Resource exhaustion
CVE-2026-22045
CWE-400 Medium
No
No
2.11.35, 3.6.7 05.05.2026 SB2026050530
#VU129662 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2025-54386
CWE-22 Low
No
No
2.11.28, 3.4.5, 3.5.0 05.05.2026 SB2026050529


Showing elements 21 - 40 out of 74