{"id":"CVE-2025-47952","aliases":["GHSA-vrch-868g-9jx5","GO-2025-3719"],"url":"https://o3.security/vulnerability/CVE-2025-47952","summary":"Traefik allows path traversal using url encoding","details":"Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. Prior to versions 2.11.25 and 3.4.1, there is a potential vulnerability in Traefik managing the requests using a PathPrefix, Path or PathRegex matcher. When Traefik is configured to route the requests to a backend using a matcher based on the path, if the URL contains a URL encoded string in its path, it’s possible to target a backend, exposed using another router, by-passing the middlewares chain. This issue has been patched in versions 2.11.25 and 3.4.1.","published":"2025-05-30T03:37:12.685Z","modified":"2026-08-08T03:48:14.590860840Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/traefik/traefik/v3","fixedVersion":"3.4.1"},{"ecosystem":"Go","name":"github.com/traefik/traefik/v2","fixedVersion":"2.11.25"},{"ecosystem":"Go","name":"github.com/traefik/traefik","fixedVersion":null}],"fix":{"url":"https://github.com/traefik/traefik/commit/08d5dfee0164aa54dd44a467870042e18e8d3f00","label":"traefik/traefik@08d5dfe"},"references":[{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v2.11.25"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.4.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/47xxx/CVE-2025-47952.json"},{"type":"ADVISORY","url":"https://github.com/traefik/traefik/security/advisories/GHSA-vrch-868g-9jx5"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-47952"},{"type":"FIX","url":"https://github.com/traefik/traefik/commit/08d5dfee0164aa54dd44a467870042e18e8d3f00"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:48:14.590860840Z"}}