Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-x677-9fxg-v5c5
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth 23 hours ago
  • Fix available
  • Severity - 7.8 (High)
GHSA-cxjq-mrr5-89rv
  • Go/github.com/traefik/traefik
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware 23 hours ago
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-8rxv-jg7p-wvg3
  • Go/github.com/traefik/traefik/v3
Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass 23 hours ago
  • Fix available
  • Severity - 7.8 (High)
GHSA-6p8f-p8j2-rqmv
  • Go/github.com/traefik/traefik/v3
Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port 23 hours ago
  • Fix available
  • Severity - 6.3 (Medium)
GHSA-62fc-8686-hfmq
  • Go/github.com/traefik/traefik
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef 23 hours ago
  • Fix available
  • Severity - 4.8 (Medium)
GHSA-3q9r-p662-5j8m
  • Go/github.com/traefik/traefik
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false 23 hours ago
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-fgjj-px3w-67xx
  • Go/github.com/traefik/traefik/v3
Traefik: Gateway API route identity collision allows cross-namespace backend hijacking 23 hours ago
  • Fix available
  • Severity - 8.2 (High)
GHSA-6765-c87h-8mrf
  • Go/github.com/traefik/traefik/v3
Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing 23 hours ago
  • Fix available
  • Severity - 2.1 (Low)
GHSA-3ccp-42pg-hgv6
  • Go/github.com/traefik/traefik
  • Go/github.com/traefik/traefik/v2
  • Go/github.com/traefik/traefik/v3
Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool yesterday
  • Fix available
  • Severity - 7.0 (High)
GHSA-42cj-m3vj-89wv
  • Go/github.com/traefik/traefik/v3
Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-qq9q-x9w4-chhj
  • Go/Traefik
Traefik Gateway API HTTPRoute BackendRef ExtensionRef Namespace Confusion yesterday
  • Fix available
  • Severity - 5.3 (Medium)
GHSA-7p4m-qxvv-g567
  • Go/github.com/rclone/rclone
rclone: Local Encoding Path Traversal yesterday
  • Fix available
  • Severity - 6.9 (Medium)
GHSA-4vr5-p2gc-h23p
  • Go/github.com/rclone/rclone
rclone archive extract allows S3 destination prefix escape via crafted archive paths yesterday
  • Fix available
  • Severity - 5.0 (Medium)
GHSA-gx4c-2hqx-cw2r
  • Go/github.com/rclone/rclone
rclone: S3 backend does not strip X-Amz-Security-Token on a same-host HTTPS->HTTP redirect yesterday
  • Fix available
  • Severity - 3.1 (Low)
GHSA-fqj9-69pf-6pjg
  • Go/github.com/rclone/rclone
rclone `serve restic --private-repos` authorization bypass: `..` in the URL path lets an authenticated user read, overwrite and delete other users' repositories yesterday
  • Fix available
  • Severity - 8.8 (High)
GHSA-2m8m-jhrm-w6j2
  • Go/github.com/rclone/rclone
rclone: PowerShell Smart-Quote Filename Injection Enables SFTP Server-Side Command Execution yesterday
  • Fix available
  • Severity - 8.0 (High)