Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| github.com/traefik/traefik/v2(Go) | 0 | 2.11.14 | N/A |
| github.com/traefik/traefik/v3(Go) | 0 | 3.2.1 | N/A |
CVSS Metrics