traefik
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 85 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from August 21, 2018 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
Traefik: ForwardAuth identity spoofing via dot-form header alias
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
Traefik HTTP/3 Backend NTLM Connection Reuse
Traefik entrypoint header-name sanitization bypassed via request trailers
Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass
Traefik before v2.11.56 Identity Spoofing via Header Alias
Traefik v3.7.0 Authentication Bypass via from-to-www-redirect
Monitor traefik in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.