An open API service providing security vulnerability metadata for many open source software ecosystems.

go

github.com/traefik/traefik/v2

go

View on github.com · View on proxy.golang.org

Security Advisories for github.com/traefik/traefik/v2 in go

Moderate
18 days ago

Traefik: A timing side-channel vulnerability allows for valid username enumeration via BasicAuth middleware GSA_kwCzR0hTQS02eDJxLWgzY3ItOGoyaM4ABVxI

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
18 days ago

Traefik has an StripPrefixRegex Middleware Authorization Bypass via Path/RawPath Desync GSA_kwCzR0hTQS02and4LTd2cDQtOTg0N84ABVw-

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
18 days ago

Traefik: Pre-authentication decision bypass due to forwarded alias spoofing GSA_kwCzR0hTQS01bTZ3LXd2aDctNTd2bc4ABVw7

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
18 days ago

Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication GSA_kwCzR0hTQS02Mzg0LW0ybXctcmY1NM4ABVw6

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Moderate
about 2 months ago

Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField GSA_kwCzR0hTQS1xcjk5LTc4OTgtdnI3Y84ABUZl

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
about 2 months ago

Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass GSA_kwCzR0hTQS02N2p4LXI5cHYtOThyas4ABUYc

go github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Moderate
about 2 months ago

Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration GSA_kwCzR0hTQS1nM2hnLWo0anYtY3dmcs4ABT6k

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
High
about 2 months ago

Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config GSA_kwCzR0hTQS13dnZxLXdnY3ItOXE0OM4ABT6j

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
2 months ago

Traefik: HTTP/2 frames can cause a running server to panic GSA_kwCzR0hTQS00aGpxLTloNWMtMjUyas4ABTi6

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
2 months ago

Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS GSA_kwCzR0hTQS1mdzQ1LWY1cTItMnA0eM4ABTG6

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
High
3 months ago

Traefik affected by TLS ClientAuth Bypass on HTTP/3 GSA_kwCzR0hTQS1ndjhyLTlydzktOTY5N84ABSsS

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
Moderate
4 months ago

Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall GSA_kwCzR0hTQS1jd2ptLTNmN2gtOWh3cc4ABRJc

go github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
about 1 year ago

Traefik has a possible vulnerability with its path matchers GSA_kwCzR0hTQS02cDY4LXc0NWctNDhqN84ABHEL

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2, github.com/traefik/traefik
Critical
about 1 year ago

Traefik affected by Go HTTP Request Smuggling Vulnerability GSA_kwCzR0hTQS01NDIzLWpjam0tMmdwds4ABHCP

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
over 1 year ago

Traefik affected by CVE-2024-53259 GSA_kwCzR0hTQS1oeHI2LTJwMjQtaGY5OM4ABChW

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
over 1 year ago

Traefik's X-Forwarded-Prefix Header still allows for Open Redirect GSA_kwCzR0hTQS1oOTI0LThnNjUtajl3Z84ABB_B

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Critical
over 1 year ago

HTTP client can manipulate custom HTTP headers that are added by Traefik GSA_kwCzR0hTQS02MmM4LW1oNTMtNGNxds4AA_sN

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Moderate
almost 2 years ago

Traefik has unexpected behavior with IPv4-mapped IPv6 addresses GSA_kwCzR0hTQS03am13LTgyNTktcTlqeM4AA88x

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
Moderate
about 2 years ago

Traefik affected by HTTP/2 CONTINUATION flood in net/http GSA_kwCzR0hTQS03ZjRqLTY0cDYtNWg1ds4AA7BQ

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
High
about 2 years ago

Traefik vulnerable to denial of service with Content-length header GSA_kwCzR0hTQS00dnd4LTU0bXctdnFmd84AA69W

go github.com/traefik/traefik, github.com/traefik/traefik/v2, github.com/traefik/traefik/v3
High
over 2 years ago

Traefik docker container using 100% CPU GSA_kwCzR0hTQS02ZndnLWpyZnctZmY3cM4AA3kw

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
over 2 years ago

Traefik vulnerable to potential DDoS via ACME HTTPChallenge GSA_kwCzR0hTQS04Zzg1LXdocWgtY3IyZs4AA3kv

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
over 2 years ago

Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass GSA_kwCzR0hTQS1mdmhqLTRxZmgtcTJobc4AA3ku

go github.com/traefik/traefik/v3, github.com/traefik/traefik/v2
Moderate
about 4 years ago

Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLTZxcTgtNXdxMy04NnJw

go github.com/containous/traefik/v2/pkg/api, github.com/containous/traefik/api, github.com/traefik/traefik/v2/pkg/api, github.com/traefik/traefik/api, github.com/containous/traefik/v2, github.com/traefik/traefik/v2, github.com/containous/traefik, github.com/traefik/traefik
High
over 4 years ago

Improper Authentication MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLXE5bXAtNzljcC05Zzhq

go github.com/traefik/traefik/v2
Moderate
almost 5 years ago

Header dropping in traefik MDE2OlNlY3VyaXR5QWR2aXNvcnlHSFNBLW02OTctNHY4Zi01NXFn

go github.com/traefik/traefik, github.com/traefik/traefik/v2