Networking

Traefik: what changed

In the last 90 days, 43 summarized changes: 31 security advisories, 2 end-of-life notices, 10 fixes. Stackdiff reads Traefik's own feeds (traefik.io) and writes two sentences per change with a link to the source; it never republishes release notes. Sources last checked .

Needs attention

Breaking changes, security advisories, end-of-life and license changes from the last 90 days, worst first.

2.11.52Securitycritical
GHSA-cxjq-mrr5-89rv: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware
2.11.53Securitycritical
GHSA-3ccp-42pg-hgv6: Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool
2.11.51Securitycritical
GHSA-9cr8-q42q-g8m7: Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts
2.11.57Securityhigh
GHSA-w4v4-9rw7-5326: Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
3.7.13Securityhigh
GHSA-v67p-phpq-fc8x: Traefik entrypoint header-name sanitization bypassed via request trailers
2.11.56Securityhigh
GHSA-7ghq-v6jf-g56c: Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
2.11.51Securityhigh
GO-2026-5287: Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
2.11.51Securityhigh
GHSA-x677-9fxg-v5c5: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
3.7.8Securityhigh
GHSA-8rxv-jg7p-wvg3: Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass
2.11.51Securityhigh
GHSA-3q9r-p662-5j8m: Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
3.6.25Securityhigh
GHSA-fgjj-px3w-67xx: Traefik: Gateway API route identity collision allows cross-namespace backend hijacking
3.7.5Securityhigh
GHSA-4mr2-fg2p-w63c: Traefik Kubernetes Ingress NGINX provider fails open when auth-secret resolution fails

End of life

Support windows from endoflife.date. An entry appears the day a date enters the 120-day horizon.

CycleWhatPublished
2.11Traefik 2.11 reached end of life on 2026-09-07
3.6Traefik 3.6 reached end of life on 2026-08-16

Latest changes

Newest first, every type. Releases and fixes sit below anything that can hurt you in the weekly brief; here they are in order.

News
Another way to leak traffic on Android has been discovered
2.11.57Securityhigh
GHSA-w4v4-9rw7-5326: Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
3.7.13Securityhigh
GHSA-v67p-phpq-fc8x: Traefik entrypoint header-name sanitization bypassed via request trailers
2.11.57Securitymedium
GHSA-qqjf-53cj-pwvv: Traefik HTTP/3 Backend NTLM Connection Reuse
2.11.57Securitymedium
GHSA-f52w-8j3h-j724: Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
2.11.56Securitymedium
GHSA-rf44-j88r-hh8c: Traefik: ForwardAuth identity spoofing via dot-form header alias
2.11.56Securityhigh
GHSA-7ghq-v6jf-g56c: Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
3.7.13Fix
v3.7.13
2.11.57Fix
v2.11.57
2.11End of lifehigh
Traefik 2.11 reached end of life on 2026-09-07
ActionPlan the upgrade before the date.
News
Flock used >100 times to track veteran who recorded traffic stop
News
A walkable ASCII cyberpunk city in one HTML file [video]
3.7.12Fix
v3.7.12
2.11.56Fix
v2.11.56
3.7.11Fix
v3.7.11
2.11.55Fix
v2.11.55
3.6.23Securitymedium
GO-2026-6192: Traefik CRD IngressRouteTCP ServersTransport Cross-Provider Namespace Bypass in github.com/traefik/traefik
2.11.51Securitymedium
GO-2026-6202: Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false in github.com/traefik/traefik
2.11.54Securitymedium
GO-2026-6203: Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef in github.com/traefik/traefik
3.6.25Securitymedium
GO-2026-6204: Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing in github.com/traefik/traefik
3.7.6Securitymedium
GO-2026-6205: Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port in github.com/traefik/traefik
3.7.8Securitymedium
GO-2026-6207: Traefik: Kubernetes Ingress NGINX RewriteTarget Path Traversal Allows Route-Level Authentication Bypass in github.com/traefik/traefik
2.11.52Securitymedium
GO-2026-6208: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware in github.com/traefik/traefik
3.6.25Securitymedium
GO-2026-6209: Traefik: Gateway API route identity collision allows cross-namespace backend hijacking in github.com/traefik/traefik
2.11.51Securitymedium
GO-2026-6211: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth in github.com/traefik/t
2.11.53Securitymedium
GO-2026-6201: Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool in github.com/traefik/traefik
3.6End of lifehigh
Traefik 3.6 reached end of life on 2026-08-16
ActionPlan the upgrade before the date.
2.11.51Securityhigh
GO-2026-5287: Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts in github.com/traefik/traefik
2.11.51Securityhigh
GHSA-x677-9fxg-v5c5: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
2.11.52Securitycritical
GHSA-cxjq-mrr5-89rv: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware

Where Stackdiff reads Traefik

Only what the vendor publishes for machines. Excerpts are capped, summaries are our own two sentences, and every line links back.

Get Traefik changes in your Monday brief

Add Traefik and the rest of your stack; breaking changes and CVEs go out the moment they're seen, everything else on Monday.

Get your first brief

Other networking tools