Security officials have identified several vulnerabilities in the Traefik reverse‑proxy software that could allow attackers to bypass security policies. The alert, issued by CERT‑FR on 2 July 2026, lists affected versions: Traefik v2.11.x before v2.11.51, v3.6.x before v3.6.22, and v3.7.x before v3.7.6. The advisories (GHSA‑3q9r‑p662‑5j8m, GHSA‑6p8f‑p8j2‑rqmv, GHSA‑x677‑9fxg‑v5c5) were published on 1 July 2026 and reference CVE‑2026‑54763, CVE‑2026‑54764 and CVE‑2026‑54765. The vulnerabilities allow policy bypass, potentially exposing systems to unauthorized access. Administrators are urged to apply vendor‑supplied patches as detailed in the official Traefik security bulletins. For more information, consult the cited advisories and CVE records. The updates fix the underlying code flaws that facilitate the bypass.
Summary of content from
Made by AI. If you spot anything of concern write us at contact@cybach.com. We’ll promptly correct irregularities.