BlackKite: Home
Menu

PUBLISHED DATE: May 30, 2025CVE-2025-47952:
Traefik (pronounced traffic) is...

CVSS:
2.9
EPSS:
2.40%
Exploitability:
0
In KEV:
No
Description

Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if the URL contains a URL encoded string in its path, it’s possible to target a backend, exposed using another router, by-passing the middlewares chain. This issue has been patched in versions 2.11.25 and 3.4.1.

Questions to Ask Vendors
  1. Can you confirm whether your systems are affected by CVE-2025-47952, and if so, what steps are you currently taking to mitigate this vulnerability?
  2. What is your estimated timeline for fully resolving CVE-2025-47952 in your products or services, and how will you communicate updates on this issue to us as your customer?
Recommended Actions
References

Ready to get results you can trust?