PT-2025-49684 · Traefik+1 · Traefik+1

Published

2025-12-08

·

Updated

2026-02-03

·

CVE-2025-66490

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 2.11.32 and 2.11.31 through 3.6.2
Description Traefik is an HTTP reverse proxy and load balancer. Requests using PathPrefix, Path, or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containing URL-encoded restricted characters (/, , Null, ;, ?, #) can bypass the middleware chain and reach unintended backends. For example, a request to http://mydomain.example.com/admin%2F could reach service-a without triggering security controls for the /admin/ path. This allows attackers to bypass path normalization checks, potentially leading to unauthorized access or request manipulation.
Recommendations Traefik versions prior to 2.11.32 should be updated to version 2.11.32 or later. Traefik versions 2.11.31 through 3.6.2 should be updated to version 3.6.3 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2025-66490
GHSA-GM3X-23WP-HC2C
GO-2025-4206
OPENSUSE-SU-2026:10020-1
OPENSUSE-SU-2026:10143-1
SUSE-SU-2026:0037-1

Affected Products

Alt Linux
Traefik