# CVE vulnerabilities for traefik:v2.9.5 - CVE-2021-41803, CVE-2022-40716, CVE-2022-32149

**URL:** <https://community.traefik.io/t/cve-vulnerabilities-for-traefik-v2-9-5-cve-2021-41803-cve-2022-40716-cve-2022-32149/16759>\
**Category:** Traefik v2\
**Tags:** kubernetes-ingress, middleware\
**Created:** [December 9, 2022, 2:40am UTC](https://community.traefik.io/t/cve-vulnerabilities-for-traefik-v2-9-5-cve-2021-41803-cve-2022-40716-cve-2022-32149/16759 "2022-12-09T02:40:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![bbsclient](https://avatars.discourse-cdn.com/v4/letter/b/dc4da7/32.png) [@bbsclient](https://community.traefik.io/u/bbsclient)\
**Post date:** [December 9, 2022, 2:40am UTC](https://community.traefik.io/t/cve-vulnerabilities-for-traefik-v2-9-5-cve-2021-41803-cve-2022-40716-cve-2022-32149/16759/1 "2022-12-09T02:40:09Z")

</div>

Below are vulnerabilities that were detected in the traefik(v2.9.5) image by the trivy vulnerability scanner.

Component: consul, version: v1.10.4, CVE-2021-41803 & CVE-2022-40716

Component: [http://golang.org/x/text](http://golang.org/x/text), version: v0.3.7, CVE-2022-32149

I did see other CVE's in Trefik's forum and Github related to Consul and the Go Text library marked as a false positive but I didn't see a mention of these specific CVEs.

Could someone please confirm if these are false positives or not?

---

<div class="post-metadata">

**Author:** ![ldez](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ldez/32/5_2.png) [@ldez](https://community.traefik.io/u/ldez)\
**Post date:** [December 9, 2022, 8:28am UTC](https://community.traefik.io/t/cve-vulnerabilities-for-traefik-v2-9-5-cve-2021-41803-cve-2022-40716-cve-2022-32149/16759/2 "2022-12-09T08:28:00Z")

</div>

Hello,

We are not affected by:

- [CVE-2022-32149](https://www.cve.org/CVERecord?id=CVE-2022-32149)
- [CVE-2021-41803](https://www.cve.org/CVERecord?id=CVE-2021-41803)
- [CVE-2022-40716](https://www.cve.org/CVERecord?id=CVE-2022-40716)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex020/uploads/containo/original/2X/b/bd81ebdb578656e76e56ff3cc3eed021d3ba132d.png) [@system](https://community.traefik.io/u/system)\
**Post date:** [December 12, 2022, 8:28am UTC](https://community.traefik.io/t/cve-vulnerabilities-for-traefik-v2-9-5-cve-2021-41803-cve-2022-40716-cve-2022-32149/16759/3 "2022-12-12T08:28:01Z")

</div>

This topic was automatically closed 3 days after the last reply. New replies are no longer allowed.
