CPE
Traefik HTTP/3 Backend Authentication Bypass via Connection Reuse
1 rule 2 TTPs 1 CVETraefik fails to isolate connection-bound NTLM and Negotiate authentication on HTTP/3 routes, allowing unrelated clients to inherit victim-authenticated backend connections.
Traefik Kubernetes Provider Authentication Bypass
1 TTP 1 CVEA vulnerability in the Traefik Kubernetes ingress-nginx provider allows unauthenticated access to backend services by bypassing middleware when specific host and annotation configurations are used.
Service Exhaustion via Stalled TLS ALPN Handshakes
1 TTP 2 CVEs 2 IOCsAttackers are exploiting unpatched TLS listeners by flooding them with incomplete ACME ALPN handshakes to exhaust server-side resources like goroutines and worker threads.
Traefik ForwardAuth Authentication Bypass via Header Spoofing
2 rules 1 TTP 2 CVEsTraefik's `ForwardAuth` and snippet-based authentication middleware has a high severity authentication bypass vulnerability because it does not sanitize header aliases with underscores, allowing attackers to spoof trust context and bypass authentication on protected routes.