CVE-2025-47952

CRITICAL

Traefik < 2.11.25 - Path Traversal

Title source: rule
STIX 2.1

Description

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if the URL contains a URL encoded string in its path, it’s possible to target a backend, exposed using another router, by-passing the middlewares chain. This issue has been patched in versions 2.11.25 and 3.4.1.

Scores

CVSS v3 9.1
EPSS 0.0040
EPSS Percentile 60.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (4)
traefik/traefik < 2.11.25
traefik/traefik 0Go
traefik/traefik 0 - 2.11.25Go
traefik/traefik 0 - 3.4.1Go
Published May 30, 2025
Tracked Since Feb 18, 2026