Traefik Patch Release Fixes Security Flaw and Critical Middleware Bugs

imagem 17

This Traefik release addresses an important security vulnerability (CVE) and brings stability improvements for users, particularly those running Kubernetes. A patch has been applied to resolve the issue detailed in advisory GHSA-8rxv-jg7p-wvg3, ensuring a safer default configuration.

Several bug fixes target middleware and Kubernetes integrations. A missing field in the ErrorRequestHeaders for CRDs has been added, and the ingress-nginx provider now properly sanitizes rewritten targets. The retry middleware no longer panics when combined with WebSocket connections, and spurious log errors from non-existent certificate resolvers have been eliminated.

Documentation updates clarify Kubernetes certificate references and port indications, correct syntax notes in routing rules, and resolve a duplicated options table in the ServersTransport CRD reference, making it easier for operators to configure their ingress with confidence.

Leave a Comment

Your email address will not be published. Required fields are marked *