PT-2025-49684 · Traefik+1 · Traefik+1

CVE-2025-66490

·

Publicado

2025-12-08

·

Atualizado

2026-07-30

CVSS v4.0

6.9

Média

VetorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 2.11.32 and 2.11.31 through 3.6.2
Description Traefik is an HTTP reverse proxy and load balancer. Requests using PathPrefix, Path, or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containing URL-encoded restricted characters (/, , Null, ;, ?, #) can bypass the middleware chain and reach unintended backends. For example, a request to http://mydomain.example.com/admin%2F could reach service-a without triggering security controls for the /admin/ path. This allows attackers to bypass path normalization checks, potentially leading to unauthorized access or request manipulation.
Recommendations Traefik versions prior to 2.11.32 should be updated to version 2.11.32 or later. Traefik versions 2.11.31 through 3.6.2 should be updated to version 3.6.3 or later.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2025-66490
GHSA-GM3X-23WP-HC2C
GO-2025-4206
OPENSUSE-SU-2026:10020-1
OPENSUSE-SU-2026:10143-1
OPENSUSE-SU-2026:21483-1
SUSE-SU-2026:0037-1

Produtos afetados

Alt Linux
Traefik