CVE-2018-15598: Traefik

High severity, CVSS 7.5. EPSS: 2.9% chance of exploitation in the next 30 days.

Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.

Affected products

  • Traefik Traefik: from 1.6.0, before 1.6.6 (fixed in 1.6.6)

Published 2018-08-21. Last modified 2026-06-17.