Database/Container, Kubernetes & orchestration
Traefik: StripPrefix middleware allows route-level authentication bypass
CVSS 7.8CVE-2026-48020Container, Kubernetes & orchestrationcurated
Impact
StripPrefix middleware allows route-level authentication bypass
Who can reach it
Unauthenticated network
What to do
Rolling Traefik upgrade to 2.11.48/3.6.19/3.7.3+
References
Related entries
- Traefik: HTTP/3 QUIC TLS configuration selection lets clients bypass router-specific mTLS enforcementCVE-2026-53622 · TraefikHigh
- Traefik: Authentication bypass via path traversal in ReplacePathRegexCVE-2026-65600 · TraefikHigh
- Traefik: GET with a Content-Length header hangs the endpoint indefinitelyCVE-2024-28869 · TraefikHigh
- Traefik: IP allow-lists bypassed via HTTP/3 early data in QUIC 0-RTT with spoofed addressesCVE-2024-39321 · TraefikHigh
- Traefik: Path traversal in the WASM plugin installation mechanismCVE-2025-54386 · TraefikHigh
- Traefik: A tenant with HTTPRoute creation rights exposes the REST provider handler, bypassing provider isolationCVE-2026-44774 · TraefikMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.