On August 26, 2026, we patched the following vulnerabilities in Traefik Proxy 2.11.56 and 3.7.12:
- Advisory GHSA-cjr6-pf59-jq29 (CVE pending) — fixed in 3.7.12
- Advisory GHSA-7ghq-v6jf-g56c (CVE pending) — fixed in 2.11.56 and 3.7.12
- Advisory GHSA-rf44-j88r-hh8c (CVE pending) — fixed in 2.11.56 and 3.7.12
Two notes on this update:
- The fix for GHSA-rf44-j88r-hh8c is a new entry point option,
aliasHeadersStrategy. It defaults tokeep, which preserves the previous behavior, so upgrading alone does not change anything: set it todeleteorrejecton your entry points for the mitigation to take effect. See Headers with Aliasing Names. - Traefik 3.6 reached end of security support on August 16, 2026 and does not receive a patch for these advisories. If you are on 3.6 or older, upgrade to 3.7.12. Traefik 2.11 reaches end of security support on September 7, 2026.
If you have any questions or comments about these vulnerabilities, please add a comment.