# New Security Update for Traefik 2.11 (2.11.35), and 3.6 (3.6.7)

**URL:** <https://community.traefik.io/t/new-security-update-for-traefik-2-11-2-11-35-and-3-6-3-6-7/29579>\
**Category:** Announcements\
**Created:** [January 15, 2026, 8:25pm UTC](https://community.traefik.io/t/new-security-update-for-traefik-2-11-2-11-35-and-3-6-3-6-7/29579 "2026-01-15T20:25:31Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicomengin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/nicomengin/32/5507_2.png) [@nicomengin](https://community.traefik.io/u/nicomengin)\
**Post date:** [January 15, 2026, 8:25pm UTC](https://community.traefik.io/t/new-security-update-for-traefik-2-11-2-11-35-and-3-6-3-6-7/29579/1 "2026-01-15T20:25:31Z")

</div>

On January 14, 2026, we patched the following vulnerability with Traefik Proxy 2.11.35 and 3.6.7:

- [CVE-2026-22045](https://nvd.nist.gov/vuln/detail/CVE-2026-22045) (Advisory [GHSA-cwjm-3f7h-9hwqj](https://github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwq))

⚠ **Breaking change** ⚠  
As explained in the comment left on the [CVE-2025-66490 fix](https://github.com/traefik/traefik/pull/12360#issuecomment-3729140469), this new hotfix version makes the behavior opt-in.  
As a result, this release is breaking compared to the previous hotfix versions since [v3.6.4](https://github.com/traefik/traefik/releases/tag/v3.6.4) ([v2.11.32](https://github.com/traefik/traefik/releases/tag/v2.11.32)), but it restores by default the behavior that existed before that hotfix.  
Please read the [migration guide v3.6](https://doc.traefik.io/traefik/v3.6/migrate/v3/#v367) or [v2.11](https://doc.traefik.io/traefik/v2.11/migration/v2/#encoded-characters-configuration-default-values) to enable the feature.

If you have any questions or comments about this vulnerability or the behavior change, please add a comment.
