8.6 KiB
8.6 KiB
Traefik
LAB ONLY|AUTHORIZED TARGETS ONLY| 自动生成索引
- 系统 ID:
traefik - 分类:
servers - 覆盖策略:
rolling-24m - 总案例数:
48 - 近 30 天新增/更新:
11 - 重点 Markdown 案例数:
0 - 已实证(真实版本):
0 - 已实证(synthetic):
0 - 阻塞数:
0 - 待人工/缺浏览器证据:
48 - 最近渲染时间:
2026-04-02T09:18:51+00:00
目标约束
- 适用目标类型:
lab-local, lab-public, authorized-third-party - 是否允许公网验证:
yes, but ownership or authorization is required - 授权前提: 资产归属可证明,或已取得书面/明确授权。
- 最小化验证方式: 最小化验证、只读探测、可审计回显、受控注入。
- 禁止场景: 无归属证明或无明确授权的公网目标;知名公共网站或与测试无关的第三方资产;会造成持久破坏、数据越权下载或不可回滚影响的动作
来源
officialGitHub Traefik Advisories (mode=server)officialOSV Traefik (mode=server)
案例列表
| 标题 | 严重度 | 案例状态 | 实证状态 | 实证方式 | 来源置信度 | 更新时间 | 案例页 |
|---|---|---|---|---|---|---|---|
| Traefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186) | medium |
generated |
triage-manual |
synthetic |
official |
2026-03-29T15:49:22.073498Z |
- |
| Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField | medium |
generated |
triage-manual |
synthetic |
official |
2026-03-27T20:49:46.252668Z |
- |
| Traefik has Knative Ingress Rule Injection that Allows Host Restriction Bypass | medium |
generated |
triage-manual |
synthetic |
official |
2026-03-27T18:03:26.283891Z |
- |
| Traefik Affected by BasicAuth Middleware Timing Attack Allows Username Enumeration | medium |
generated |
triage-manual |
synthetic |
official |
2026-03-23T18:56:05.020639Z |
- |
| Traefik has a Potential mTLS Bypass via Fragmented TLS ClientHello Causing Pre-SNI Sniff Fallback to Default Non-mTLS TLS Config | medium |
generated |
triage-manual |
synthetic |
official |
2026-03-23T18:56:07.286130Z |
- |
| Traefik: kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-23T04:52:53.505590Z |
- |
| Traefik: HTTP/2 frames can cause a running server to panic in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-23T04:52:55.119301Z |
- |
| Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-23T04:53:12.392934Z |
- |
| Traefik: tcp router clears read deadlines before tls forwarding, enabling stalled handshakes (Slowloris DOS) in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-23T04:53:12.548643Z |
- |
traefik CVE-2024-45410 fix bypass: lowercase Connection tokens can delete traefik-managed forwarded identity headers (for example, X-Real-Ip) in github.com/traefik/traefik |
unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-23T04:53:13.381024Z |
- |
| Traefik affected by TLS ClientAuth Bypass on HTTP/3 | low |
generated |
triage-manual |
synthetic |
official |
2026-03-13T10:47:38.380633Z |
- |
| Traefik: TCP readTimeout bypass via STARTTLS on Postgres | low |
generated |
triage-manual |
synthetic |
official |
2026-02-25T14:44:05.939193Z |
- |
| Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:57:52.435901Z |
- |
| Path Normalization Bypass in Traefik Router + Middleware Rules in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:57:45.825626Z |
- |
| Traefik Inverted TLS Verification Logic in ingress-nginx Provider in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:57:46.762301Z |
- |
| Traefik allows path traversal using url encoding in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:56:38.338929Z |
- |
| Traefik has a possible vulnerability with the path matchers in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:56:30.468018Z |
- |
| Traefik affected by Go HTTP Request Smuggling Vulnerability in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:56:31.085358Z |
- |
| Traefik affected by CVE-2024-53259 in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:56:09.454939Z |
- |
| HTTP client can manipulate custom HTTP headers that are added by Traefik in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:55:48.536445Z |
- |
| Bypassing IP allow-lists in traefik via HTTP/3 early data requests in QUIC 0-RTT handshakes in github.com/traefik/traefik | unknown |
generated |
triage-manual |
synthetic |
official |
2026-03-03T04:55:33.607072Z |
- |
| Issues | |||||||
| 678 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| TCP readTimeout bypass via STARTTLS on Postgres | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Policy | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Report a vulnerability | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Inverted TLS Verification Logic in Kubernetes NGINX Provider | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| traefik | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Sign in | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Next | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Security | |||||||
| 35 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Pull requests | |||||||
| 95 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Sign up | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| 3 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| traefik | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Skip to content | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| HTTP/2 frames can cause a running server to panic | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| 4 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| ForwardAuth Middleware Allows Unbounded Response Body, Causing Potential Denial of Service | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| ACME TLS-ALPN fast path lacks timeouts and close on handshake stall | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Projects | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Path Normalization Bypass in Traefik Router + Middleware Rules | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Actions | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Case-Sensitive Bypass in Connection Header Allows Removal of X-Forwarded Headers | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Insights | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| TLS Handshake Error Handling Allows Stalled Connections on TCP Routers | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Kubernetes gateway rule injection via unescaped backticks in HTTPRoute match values | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| TLS ClientAuth Bypass on HTTP/3 | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |
| Star | |||||||
| 62.2k | unknown |
triage |
triage-manual |
synthetic |
official |
`` | - |