CVE-2025-66490 - CVE House
Back to Database
Status published Medium CVE-2025-66490

Traefik doesn't Prevent Path Normalization Bypass in Router + Middleware Rules

Vulnerability Description

Traefik is an HTTP reverse proxy and load balancer. For versions prior to 2.11.32 and 2.11.31 through 3.6.2, requests using PathPrefix, Path or PathRegex matchers can bypass path normalization. When Traefik uses path-based routing, requests containing URL-encoded restricted characters (/, \, Null, ;, ?, #) can bypass the middleware chain and reach unintended backends. For example, a request to http://mydomain.example.com/admin%2F could reach service-a without triggering my-security-middleware, bypassing security controls for the /admin/ path. This issue is fixed in versions 2.11.32 and 3.6.3.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-66490

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

traefik
Vulnerable Versions:
github.com/traefik/traefik/v3 < 3.6.3, github.com/traefik/traefik/v2 < 2.11.32, github.com/traefik/traefik <= 1.7.34

Timeline

Official Publish: December 9th, 2025
Last Modified: December 9th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.