docs/content/contributing/submitting-security-issues.md
We strongly advise you to join our mailing list to be aware of the latest announcements from our security team. You can subscribe by sending an email to [email protected] or on the online viewer.
Reported vulnerabilities can be found on cve.mitre.org.
CVEs are only created for vulnerabilities affecting Generally Available (GA) versions of Traefik. Vulnerabilities discovered in non-GA versions (release candidates, betas, early access, or development branches) will be fixed without creating a CVE.
Traefik is an edge router. Its security boundary sits between untrusted network clients and the services it routes to. A report is a vulnerability when an unprivileged, untrusted client crosses that boundary. Reports that start from the other side of it describe bugs, and we fix bugs.
This threat model applies to reports submitted on or after 1 September 2026. It states positions we already apply; publishing them is meant to save you the work of rediscovering them.
With no configuration-write access and no operator privilege required:
A boundary stated this briefly does not resolve a concrete report on its own. The surfaces where we have already settled a position, each with the neighbouring variant we do treat as a vulnerability and the CVEs that prove it, are on the Security Decisions page. Check your finding there before submitting.
Some reports describe real defects that we fix, often at high priority, but that do not receive an advisory or a CVE, because they do not cross the boundary above. We say so explicitly rather than leaving it implicit, and we will point at a specific entry in Security Decisions when we close a report on these grounds.
We want to keep Traefik safe for everyone. If you've discovered a security vulnerability in Traefik, we appreciate your help in disclosing it to us in a responsible manner, by creating a security advisory.
We are committed to handling every legitimate report responsibly, and we expect submitters to engage with our security team in a respectful and collaborative manner.
The following behaviors are not acceptable and will not be tolerated:
Submitters who engage in any of the above may face the following consequences:
We take security seriously and act on legitimate reports as quickly as our resources allow. Patience and constructive dialogue help us protect users effectively.
We have been receiving an increasing number of low-quality vulnerability reports that are not actual security issues. Many of these reports originate from AI/LLM tools and are submitted without any human validation or testing. This wastes the time of our security team and delays the handling of legitimate vulnerabilities.
Before submitting a security advisory, you must:
Security reports that are directly generated by AI/LLM tools without proper human validation will be closed immediately.
Indicators of unvalidated AI-generated reports include (but are not limited to):
Contributors who repeatedly submit low-quality or unvalidated reports may have their accounts blocked.
We appreciate the work of security researchers who take the time to rigorously validate their findings. Quality over quantity helps keep Traefik safe for everyone.