Traefik security bypass flaws patched
Multiple vulnerabilities in Traefik proxy versions 2.11.x, 3.6.x, and 3.7.x allow attackers to bypass security policies; patches available.
The French CERT has disclosed multiple security policy bypass vulnerabilities affecting Traefik, a popular cloud-native application proxy and load balancer. The flaws impact three branches: versions 2.11.x prior to 2.11.51, versions 3.6.x prior to 3.6.22, and versions 3.7.x prior to 3.7.6. These vulnerabilities could allow an attacker to circumvent security controls implemented within Traefik deployments.
The vendor has released patches addressing the issues, tracked as CVE-2026-54763, CVE-2026-54764, and CVE-2026-54765. Organizations running affected Traefik versions should prioritize updating to the patched releases to prevent potential security policy bypasses. Given Traefik's widespread use in containerized and microservices environments, the exposure surface for these vulnerabilities may be significant across cloud-native infrastructure.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0823
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free