Traefik vulnerabilities
3 CVEs tracked
Traefik appears in reports as a critical API Gateway in Kubernetes environments, with integrations involving Gateway API, IngressRouteTCP, and Nginx Ingress annotations. Main events include namespace confusion (CVE-2026-65601), allowlist bypass (CVE-2026-65602), and path traversal (CVE-2026-67309) vulnerabilities, which could allow low-privileged Kubernetes users to gain unauthorized access. Defenders must immediately update Traefik to versions 3.6.23+ or 3.7.8+ and should implement log-based ES|QL rules to detect probing activity.
Azərbaycanca: Traefik, mühitdə Kubernetes Gateway API, IngressRouteTCP və Nginx Ingress annotasiyaları ilə işləyən kritik bir API Gateway kimi hesabatlarda görünür. Əsas hadisələr namespace confusion (CVE-2026-65601), allowlist bypass (CVE-2026-65602) və path traversal (CVE-2026-67309) zəiflikləri olub, bunlar aşağı imtiyazlı Kubernetes istifadəçilərinə icazəsiz məlumatlara çıxış əldə etməyə imkan verə bilər. Müdafiəçi Traefik-i dərhal 3.6.23+ və ya 3.7.8+ versiyalarına yeniləməli, həmçinin əlavə olaraq probing fəaliyyətini aşkarlamaq üçün log əsaslı ES|QL qaydalarını tətbiq etməlidir.
This vendor's CVEs3
This hub is built from skopnix's own reporting on Traefik: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.