VORANT. Threat Intelligence Sign in Get the full feed

Multiple security policy bypass vulnerabilities affect Traefik proxy versions 2.11.x…

high vulnerability

Multiple security policy bypass vulnerabilities affect Traefik proxy versions 2.11.x, 3.6.x, and 3.7.x; patches available in v2.11.48, v3.6.19, and v3.7.3.

The French CERT (CERT-FR) has disclosed multiple security policy bypass vulnerabilities in Traefik, a popular cloud-native edge router and reverse proxy. The vulnerabilities affect three major version branches: v2.11.x prior to v2.11.48, v3.6.x prior to v3.6.19, and v3.7.x prior to v3.7.3. These flaws allow an attacker to circumvent security policies enforced by Traefik, potentially enabling unauthorized access to protected resources or services.

Traefik has released security advisories (GHSA-5r4w-85f3-pw66, GHSA-9cr8-q42q-g8m7, GHSA-xf64-8mw2-4gr2) on June 5, 2026, along with patched versions addressing these issues. Two CVE identifiers have been assigned: CVE-2026-48020 and CVE-2026-48491. Organizations using affected Traefik versions should prioritize patching, as the ability to bypass security policies represents a significant risk to perimeter defense and access control mechanisms.

Given Traefik's widespread deployment in containerized and microservices environments, these vulnerabilities could impact a broad range of organizations across multiple sectors. The lack of detailed exploitation information in the advisory suggests responsible disclosure, but organizations should assume active exploitation attempts may follow public disclosure.

Mentioned in this report

Vulnerabilities CVE-2026-48020CVE-2026-48491

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0690

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free