New Security Update for Traefik 2.11 (2.11.52) and 3.7 (3.7.12)

On August 26, 2026, we patched the following vulnerabilities in Traefik Proxy 2.11.56 and 3.7.12:

Two notes on this update:

  • The fix for GHSA-rf44-j88r-hh8c is a new entry point option, aliasHeadersStrategy. It defaults to keep, which preserves the previous behavior, so upgrading alone does not change anything: set it to delete or reject on your entry points for the mitigation to take effect. See Headers with Aliasing Names.
  • Traefik 3.6 reached end of security support on August 16, 2026 and does not receive a patch for these advisories. If you are on 3.6 or older, upgrade to 3.7.12. Traefik 2.11 reaches end of security support on September 7, 2026.

If you have any questions or comments about these vulnerabilities, please add a comment.