PT-2025-49684 · Traefik+1 · Traefik+1
Published
2025-12-08
·
Updated
2026-02-03
·
CVE-2025-66490
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions prior to 2.11.32 and 2.11.31 through 3.6.2
Description
Traefik is an HTTP reverse proxy and load balancer. Requests using PathPrefix, Path, or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containing URL-encoded restricted characters (/, , Null, ;, ?, #) can bypass the middleware chain and reach unintended backends. For example, a request to
http://mydomain.example.com/admin%2F could reach service-a without triggering security controls for the /admin/ path. This allows attackers to bypass path normalization checks, potentially leading to unauthorized access or request manipulation.Recommendations
Traefik versions prior to 2.11.32 should be updated to version 2.11.32 or later.
Traefik versions 2.11.31 through 3.6.2 should be updated to version 3.6.3 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Traefik