Traefik security policy bypass flaw patched
A vulnerability in Traefik reverse proxy versions 3.6 and 3.7 can let attackers bypass security policy controls; patches are available.
ANSSI (CERT-FR) issued an advisory on a security policy bypass vulnerability affecting Traefik, the widely used cloud-native reverse proxy and load balancer. The flaw, tracked as CVE-2026-54761, impacts Traefik versions v3.6.20 and earlier in the 3.6 branch, and v3.7.4 and earlier in the 3.7 branch. Exploitation would allow an attacker to circumvent configured security policies, potentially exposing backend services or bypassing access controls enforced through Traefik.
The issue was disclosed by Traefik via GitHub Security Advisory GHSA-3g6v-2r68-prfc on June 11, 2026. Administrators running affected versions should upgrade to v3.6.21 or v3.7.5 as appropriate. No evidence of active exploitation is noted in the advisory; this is a vendor-driven patch notice rather than a confirmed in-the-wild attack.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0738
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free