Last 7 days
2
Features: 0
Changes: 0
Fixes: 2
Deprecations: 0
Cloud-native application proxy and ingress controller.
Latest Traefik changelog updates, official release notes, breaking changes, security patches, pricing changes, and developer reactions in one product feed.
Follow this Traefik release-notes page to spot useful features, risky migrations, noisy announcements, and source links before they hit your backlog.
Changes.Watch links back to official changelog and release-note sources so summaries stay easy to verify.
Use channels to follow groups of tools around a stack, workflow, or topic.
Rolling windows show how many product updates landed in the last 7, 30, 90, and 365 days, grouped by existing changelog semantics.
2
8
24
65
Fixed numerous bugs across FastProxy, HTTP3, and Kubernetes CRD/Ingress/GatewayAPI providers, including status code handling, name collisions, and router rule fixes.
Fixed name collision issues and added safe‑naming options for the Kubernetes CRD provider, including scoped service names and namespace restriction for default TLS resources.
Bumped multiple dependencies (acme/lego, DataDog/dd-trace-go, golang.org/x/text, etc.) to newer versions.
Fixed authentication singleflight key collision and router name collisions in Kubernetes Gateway API provider.
Updated tracing library to dd-trace-go v2.8.1 and upgraded golang.org/x/text and x/net packages
Patched CVE GHSA-3ccp-42pg-hgv6, addressing a critical security issue.
Fixed CVE GHSA-3ccp-42pg-hgv6 and applied numerous bug fixes across middleware, CRDs, logs, and server CONNECT handling
Fixed CVE GHSA‑3ccp‑42pg‑hgv6 and added migration guidance for updated CONNECT request handling.
Fix CVE‑GHSA‑8rxv‑jg7p‑wvg3 security advisory
Fixed multiple CVEs (GHSA‑cxjq‑mrr5‑89rv, GHSA‑42cj‑m3vj‑89wv, GHSA‑qq9q‑x9w4‑chhj).
CVE fixes addressing GHSA‑cxjq‑mrr5‑89rv and GHSA‑42cj‑m3vj‑89wv
Fixed CVE GHSA‑cxjq‑mrr5‑89rv
Patched CVE-2026-54763, CVE-2026-54764, and CVE-2026-54765 and fixed nondeterministic TLS certificate selection on shared SANs.
Fixed critical CVE‑2026‑54763 and CVE‑2026‑54764 and added HTTP/2 header memory exhaustion security documentation.
Fixed CVE-2026-54763 and CVE-2026-54764 security vulnerabilities
Patched CVE‑2026‑54761 and CVE‑2026‑54762 (GHSA advisories).
Fixed CVE‑2026‑54761 (GHSA‑3g6v‑2r68‑prfc) addressing a security vulnerability.
Fixed TLS router handling when the same host uses different TLS options across entry points.
Fixed Redis write timeout option handling in middleware
Fixed Redis write timeout option configuration in middleware and corrected BackendTLSPolicy status updates
Updated quic-go dependency to v0.59.1 for HTTP/3 stability.
Fixed critical CVEs (2026‑48020, 2026‑48491, 2026‑53622) and updated several dependencies for security hardening
Patched security vulnerability CVE‑2026‑48020 (GHSA‑xf64‑8mw2‑4gr2).
Fix CVE‑2026‑48020 (GHSA‑xf64‑8mw2‑4gr2).
Patched CVE‑2026‑44774 (GHSA‑96qj‑4jj5‑wcjc) to address a security vulnerability.
Fixed CVE‑2026‑44774 (GHSA‑96qj‑4jj5‑wcjc)
Fixed CVE‑2026‑44774 (GHSA‑96qj‑4jj5‑wcjc) addressing a security issue
- Added extensive ingress‑nginx enhancements: dynamic metamodel config, limit connections/burst, auth snippet, wildcard hosts, numerous new annotation support (limit rpm/rps, buffering, canary, custom headers, TLS auth, rewrite targets, ...
Remove cross‑provider sanitization for Kubernetes service loading (bug fix)
Removed cross‑provider sanitization for Kubernetes service loading (k8s/crd).
Fixed CVE‑2026‑41181 (GHSA‑p6hg‑qh38‑555r)
Fixed security vulnerability CVE‑2026‑41181 (GHSA‑p6hg‑qh38‑555r).
Breaking change: Chain middleware CRDs now enforce allowCrossNamespace (default false), rejecting cross‑namespace references; review configs before upgrading.
- Patched multiple critical CVEs (2026‑40912, 2026‑39858, 2026‑35051, 2026‑41263, 2026‑41174); see migration guide for details.
Updated middleware dependencies and fixed TestNegotiation bug
Patched critical security issues (CVE‑2026‑33433, CVE‑2026‑33186).
Patched critical CVE-2026-33433 and CVE-2026-33186 vulnerabilities
Patched multiple high‑severity CVEs (2026‑32595, 2026‑32305, 2026‑32695) and made basic‑auth timing constant for security.
Patched CVE-2026-32595 and CVE-2026-32305 security vulnerabilities.
Patched CVE-2026-29777 and CVE-2026-27141.
Fixed CVE-2026-27141 (GHSA-4hjq-9h5c-252j) addressing a security vulnerability.
Patched multiple CVEs (2026-26998, 2026-26999, 2026-29054) addressing security vulnerabilities.
Patched multiple CVEs (2026‑26998, 2026‑26999, 2026‑29054) to address security vulnerabilities.
Patched critical vulnerabilities CVE‑2026‑25949 and CVE‑2025‑68121.
Fixed security vulnerability CVE-2025-68121 (GHSA-gv8r-9rw9-9697).
Fix recursion issue in service handling
Introduces a breaking change: encoded character options are now opt‑in, requiring migration to restore previous default behavior
Restores pre‑v2.11.32 default behavior, now requiring opt‑in which is a breaking change
Upgrade ACME and QUIC dependencies; fix Redis verification, encoded character denial, and menu item naming bugs
Fixed server issue where encoded characters were incorrectly denied.
Log rejected requests and emit warnings about the new behavior
Fixed NGINX ingress sslredirect annotation support and added access logs for rejected requests.
Fixed critical CVE-2025-66490 and CVE-2025-66491 (security patches) with a required migration guide (breaking change).
Fixed CVE‑2025‑66490 with a breaking change; migration guide must be read
Read the migration guide before upgrading.
Fixed Docker API auto‑negotiation, multi‑layer routing with models, and reduced UDP read‑loop allocations
Fix auto-negotiation of Docker API version bug.
Adds multiple new features: ACME certificate resolver options, AWS ECS IPv6 support, least‑time and highest‑random‑weight load‑balancing strategies, TCP and passive health checks, and a Knative provider.
Upgrade ACME library to go-acme/lego v4.28.0
Update several dependencies including acme/lego, quic-go, and OpenTelemetry to newer versions
Updated http3, server, and tracing dependencies (quic-go v0.55.0, golang.org/x/net v0.46.0, DataDog dd-trace-go v1.74.6) to resolve bugs and compatibility issues
Fix multiple bugs: set minimum MaxIdleConnsPerHost for servers transport, refactor plugins system, use client connection for proxy protocol header, and update web UI hub button script.
Added GenericCLF log format for access logs and new Redis options with distributed rate‑limit middleware
Fixed various bugs: added Log Body to OTEL access logs, made app protocol case‑insensitive, canonicalized tracing headers, and silenced expected SIGTERM errors.
Upgrade go-acme/lego to v4.25.2 and Docker client to v28.3.3.
Added OCSP stapling, new ACME configuration options, and post‑quantum X25519MLKEM768 TLS support
Bumped quic-go to v0.54.0 to fix HTTP/3 issues
Redact install configuration in logs to protect sensitive data
Fixed nativeLB annotation handling and concurrent balancer status map access in k8s gateway and load balancing strategies.
Update go-viper/mapstructure dependency to v2.3.0
Fix http3 bugs by bumping quic-go to v0.49.0
Enhanced documentation across several components: added notes for certificatesDuration, Ingress backend resource support, EntryPoints, Observe guides, clarified CircuitBreaker and mirroring service defaults, and introduced a WebSocket gu...
Fix middleware to avoid logging Redis sentinel usernames and passwords
Fixed CVE‑2025‑47952 and resolved numerous bugs in Docker networking, K8s CRD validation, middleware rate‑limiting, server routing, P2C strategy thread safety, and the Web UI.
Fixed CVE‑2025‑47952 (GHSA‑vrch‑868g‑9jx5) and added migration guide notice
- Added numerous new configuration options and middleware enhancements, including acme.profile/emailAddresses, Redis rate limiter, p2c load balancing, UDP routing, sticky cookie domain, and auto web UI theming.
Add SpanID and TraceID fields to access logs only when tracing is enabled.
Patched CVE‑2025‑32431, CVE‑2025‑22868, and CVE‑2025‑22871 to resolve security issues.
Fixed multiple CVE‑2025 security vulnerabilities (CVE‑2025‑32431, 22868, 22871) with advisory references
Fixed HTTPS scheme handling for BackendTLSPolicy in k8s gateway API and corrected compress middleware behavior (algorithm priority, malformed content type handling, compression on flush).
Updated multiple dependencies including AWS SDK, oxy, golang.org/x/net, jwt, redis, and jose versions.
Added WebSocket header support and updated fasthttp version in fastproxy; fixed chunked response header handling.
Updated acme and CLI dependencies to latest versions (go-acme/lego v4.22.2 and traefik/paerser v0.2.2).
Fix API to avoid creating observability model by default
Fixed graceful shutdown issue during ACME JSON write operation.
Adjusted middleware log level for missing client certs and stopped creating a logger per proxy.
Fixed HEAD request handling in fastproxy and corrected observability configuration for EntryPoints.
Disabled HTTP/2 CONNECT for WebSocket by default to fix server issues.
Disable HTTP/2 CONNECT setting for websockets by default (bug fix).
Disable HTTP/2 CONNECT for websockets by default.
Added many new configuration options (ACME propagation checks, API dump endpoint, host header handling, optional IngressRoute kind, serving endpoints, OpenTelemetry logs, observability controls, forward‑auth header preservation, basic‑au...
⚠️ Warn about websocket upgrade issue; set GODEBUG=http2xconnect=0 to use this version
⚠️ WebSocket upgrade issue requires setting GODEBUG=http2xconnect=0 as a workaround.
Update install documentation with the current chart default.
Update golang.org/x dependencies on the server component
Patched CVE‑2024‑53259 (GHSA‑hxr6‑2p24‑hf98) to resolve a security issue.
Fix CVE-2024-53259 security vulnerability
- Patched CVE‑2024‑45410 (GHSA‑h924‑8g65‑j9wg); see migration guide for required changes
Patched CVE‑2024‑45410 (GHSA‑h924‑8g65‑j9wg) – see migration guide for required changes.
Added extensive Gateway API support (BackendTLSPolicies, NativeLB, protocol selection, GRPC routes, status updates) and upgraded to v1.2.0.
Fixed preservation of HTTPRoute filter order in the Kubernetes Gateway API implementation.
Fixed panic on aborted requests in middleware/service, ensuring connections close properly.
Reused compression writers in middleware to improve performance.
Updated middleware compression library and upgraded web UI to Node 22.9 and refreshed Yarn lock to address security vulnerabilities.
Disable IngressClass lookup when `disableClusterScopeResources` is enabled, fixing related ingress issues.
Fixed multiple bugs: corrected acme defaultGeneratedCert CN handling, cleaned forward‑auth connection headers, reworked timeout logging, updated compress library, and removed unused web UI boot files.
Fix metrics detection for Datadog when using a Unix socket prefix
Update http3 component by bumping quic-go to v0.47.0.
Patched CVE‑2024‑45410 and fixed multiple bugs in Kubernetes Ingress handling, middleware capture, and plugin initialization (removed goexport).
Updated acme/lego to v4.18.0 and added support for custom routers handling ACME challenges.
Fixed Kubernetes gateway status address comparison and added option to disable cluster‑scope resource discovery.
Updated Docker client to github.com/docker/docker v27.1.1
Upgrade google.golang.org/grpc to v1.64.1 and fix gateway API route status updates.
Fixed the new version log message and enforced default TLS cipher suites.
Added extensive Kubernetes Gateway API support: new HTTPRoute status handling, method/query/regex matching, redirects with scheme/port, URL rewrite filter, reference grants, priority computation, health checks for ExternalName services, ...
Fixed CVE‑2024‑39321 security vulnerability
Address CVE‑2024‑39321 (GHSA‑gxrv‑wf35‑62w9) security issue
Patch security vulnerability (GHSA rvj4-q8q5-8grf) related to CVE‑2024‑35255.
Patched vulnerability GHSA-rvj4-q8q5-8grf linked to CVE-2024-35255.
Patched CVE GHSA‑7jmw‑8259‑q9jx (related to CVE‑2024‑24790) to resolve a security issue.
Patched CVE GHSA-7jmw-8259-q9jx (related to CVE‑2024‑24790) addressing a security vulnerability.
Patched security issues identified in CVE-2024-24788 (GHSA f7cq‑5v43‑8pwp).
Patched CVE GHSA-f7cq-5v43-8pwp (related to CVE‑2024‑24788).
Introduces numerous features: split Docker provider, weighted server load balancing, gRPC health checks, stable HTTP/3, expanded Gateway API support (cross‑namespace refs, HostSNIRegexp, upgrade to v1.0.0) and full OpenTelemetry tracing/...
Addressed critical security vulnerabilities (GHSA‑7f4j‑64p6‑5h5v, CVE‑2023‑45288, CVE‑2024‑28869); see Migration Guide.
Updated dependencies (acme/lego, quic-go, docker/cli, Yaegi, Elastic APM) and improved TLS handling (TLSStore labeling, TCP HostSNI enforcement, Lingering Timeout).
Deprecate IPWhiteList middleware, add IPAllowList with TCP constructor and introduce Redis Sentinel support plus KeepAliveMaxTime/KeepAliveMaxRequests entrypoint options
Resolved JSON formatting issue in Datadog logs.
Patched several security vulnerabilities (CVE‑2023‑45283, 45284, 47124, 47633, 47106) by refusing recursive requests, denying URL fragments, and removing backoff for the HTTP challenge.
- Implement security patch for CVE‑2023‑39325 (GitHub Advisory GHSA‑7v4p‑328v‑8v5g).
Update acme/lego library to v4.13.2/4.13.0 for bug fixes
Update go acme/lego library to v4.12.2
Updated acme/lego and DataDog tracing dependencies and applied numerous bug fixes across ACME handling, Kubernetes CRD endpoints, Prometheus cleanup, and middleware behavior (query encoding, trailer support, informational headers).
Update vulcand/oxy to commit 5cf38, fixing middleware issues.
Added native Kubernetes service load balancing and introduced traefik.io API Group CRDs; requires updating CRDs and RBAC before upgrade (breaking)
Patch for CVE‑2023‑29013, which is linked to CVE‑2023‑24534
Update key dependencies (acme/lego, quic-go, vulcand/oxy) and fix Nomad provider default config and TLS defaults
Update golang.org/x/net to v0.7.0
Fixed numerous bugs across components (acme, ecs, file provider, logs, middleware, plugins, TLS/HTTP3, TCP) improving stability and resilience
Fixed multiple security CVEs and updated related dependencies.
Fixed a bug by creating a new capture instance for each incoming request in logs and middleware.
Updated go‑acme/lego to v4.9.0 and Yaegi to v0.14.3.
Added multiple new features: ACME default certificate, Nomad canary deployments, host networking on Podman, IPv6 support, ECS Anywhere, ALPN for TCP/TLS routers, traffic size metrics, Datadog GlobalTags, and plugin config from Kubernetes...
Update golang.org/x/net to the latest version for server stability
Fixed multiple bugs including Consul catalog UDP load balancer tag handling, query parameter equality matching, websocket header processing, and allowed empty plugin configurations; simplified AddServer algorithm.
Updated Yaegi to v0.14.2 and fixed IPv6 address handling with square brackets
Fixed Docker provider memory leak on retries and corrected retry middleware panic handling.
Update parser to v0.1.8
Fixed several bugs: corrected Ingress router key ordering, fixed Prometheus service‑up gauge, removed request dump from IPWhitelist logs, and refined label allocation in metrics.
Upgraded Valkeyrie to v0.4.1 and improved Prometheus metrics performance when enabled
Added multi-namespace support for Consul providers, a new Nomad provider, TLSStore CRD certificate configuration, and HTTP/2 max concurrent stream setting.
Fixed metrics issue: Datadog client now cleanly stopped
Fixed health check handling to avoid duplicate requests, added logging for missing paths, corrected HostRegexp/Query muxers, and updated RedirectScheme to respect X‑Forwarded‑Proto
Update go acme/lego to v4.7.0 and fix invalid log placeholder
Added new integrations and capabilities: Consul event watch, experimental Traefik Hub integration, failover healthcheck, HTTP/3 advertised port configuration, InfluxDB v2 metrics backend, HostSNIRegexp matcher and TCP muxer, and support ...
Fix various bugs in logs, TCP lookup, TLS certificate handling, and external name configuration
Fixed bugs in ACME renew interval, ECS instance ID filtering, duplicate logs, middleware writeheader, large custom pages, redirect regex, buffering defaults, and preflight request handling.
Fix plugin slice parsing bug
Updated parser to v0.1.5 and fixed multiple documentation typos across acme, docker, HTTP/3, Redis, Marathon, middleware, and rules modules
Fixed bugs in ACME domain handling, metrics bucket keys, middleware SNI checks, Datadog span tags, TLS rule application, and Kubernetes TCP examples.
Added extensive configuration options across providers and middleware (ACME certificate duration, Consul enterprise namespaces, Gateway API v1alpha2, HTTP/2/3 timeouts, metric tags/prefixes, body size, retry limits, organizational unit s...
Updated acme/lego to v4.6.0 and changed log level from info to debug.
Fix processing of all X-Forwarded-For headers in middleware
Updated dependencies (acme/lego to v4.5.3, yaegi to v0.11.1) and increased UDP read buffer to max datagram size.
Enforced PEM validation for Kubernetes secrets
Update acme/lego to v4.5.0 and fix numerous middleware, TLS, and CRD issues
Fix non-cluster mode in acme component.
Fixed missing preferred chain in acme implementation.
Add support for preferred chain handling in ACME for Traefik v1
Fix several bugs in providers and metrics (consul catalog cert handling, k8s CRD peerCertURI, HTTP2 disable, IngressRoute ServersTransport, cross‑namespace verification, Prometheus metrics)
Upgrade http3 library to quic-go v0.23.0 and bump related dependencies (go.elastic.co/apm, x/sys, Alpine image)
Fixed Conditional CloseNotify handling in header middleware (middleware, http3) (8374).
Added major networking features: Consul Connect support, experimental HTTP/3, wildcard hostnames, TCPRoute/TLSRoute, cross‑provider service references, and named‑port support for IngressRoute CRDs.
Fixed unauthorized middleware cross-namespace reference in Kubernetes CRDs
Remove hop-by-hop headers defined in the connection header before middleware processing
Fixed early retrieval of Kubernetes server version and prevented ingress config removal on API call failure.
Disable ExternalName services by default on Kubernetes providers and turn off cross‑namespace support for the IngressRoute provider.
Update go‑acme/lego to v4.4.0 and fix ACME preferred chain handling.
Fix Prometheus metrics handler to use the custom registry, addressing issue 8040.
Upgrade the Go toolchain to version 1.16.
Updated key dependencies (acme/lego, gateway API, proxyproto) and added validation for non‑ASCII domain names in router rules
Fixed double close channel issue in ACME TLS challenge
Update Yaegi to v0.9.13 in the plugins component.
Fix web UI to restrict iframe sources to the same domain
Fix TLS challenge timeout and validation error in the acme module.
Fix redirect entrypoint default priority and resolve infinite loop in forwarded header middleware
Added support for multiple Kubernetes ingress classes.
Added new ACME HTTP/TLS challenge implementations with external account binding, and introduced ServersTransport support on services
Fix tracing middleware to avoid SetError on whitelisted requests
Fixed Kubernetes ingress wildcard hostname handling and optimized annotation regex compilation.
Updated Logrus to v1.7.0 and Yaegi to v0.9.8 for improved logging and scripting support.
Updated acme/lego to v4.1.3 and added option to disable cross-namespace routing for IngressRoute.
Updated go acme/lego to v4.1.2 and fixed provider slice parsing
Fixed numerous bugs across providers (ECS, Consul Catalog, Kubernetes, TCP) and updated plugins (Yaegi) to newer versions
Fixed multiple ACME issues (TLS challenge protocol, keytype handling, race condition), updated Yaegi to v0.9.4, and corrected UDP JSON struct tag.
Fixed blank web UI on certain browsers
Added new providers (AWS ECS, HTTP) and expanded Traefik Pilot with metrics, plugins support, and moved it out of experimental; introduced custom ping HTTP code and IngressClass support with RBAC docs.
Fix header middleware response writer bug.
Updated go acme/lego to v4.0.1 and corrected middleware YAML tag and header modifier behavior.
Fix: Clean X-Forwarded-Prefix header handling for the dashboard in the web UI.
Fix: Clean X-Forwarded-Prefix header handling in the Web UI dashboard.
Fixed TLS server bug where host port was incorrectly included in SNI comparisons.
Fixed case‑insensitive access log header filtering and corrected entrypoint port address handling for redirects
Fixed IPv6 handling in redirect middleware.
Fixed k8s CRD to correctly read contentType middleware into dynamic config
Fix TLS handling by updating the default value of insecureSNI (issue 7027)
Fixed panic when using chain middleware in the middleware layer.
Fixed multiple bugs across components including ACME library updates, concurrency handling, IPv6 redirects, UDP memory leak, race conditions in dynamic config, and disabled domain fronting
Multiple bug fixes across many components (acme, consulcatalog, server, websocket, udp, etc.)
Added extensive UDP support across providers, server entry points, and Web UI, plus new entry‑point redirection, default router configuration, and enhancements to TLS, middleware, and tracing features.
Fixed stickiness annotations support in Kubernetes ingress.
Fixed sameSite handling for provider sticky sessions
Fixed SameSite handling and resolved bugs across multiple integrations (consul, consulcatalog, docker, ecs, k8s, marathon, mesos, rancher, sticky session).
Fixed a memory leak in the metrics component
Fixed access log field quoting and corrected statsd scaling for duration metrics.
Fix provider redirection handling for invalid regex syntax and clear closed hijacked h2c connections on the server.
Fixed multiple bugs across providers, including Consul catalog port handling, healthcheck duplication, secret informer loading, TLS version handling, and file provider reload on Kubernetes symlinks
Fixed multiple bugs: dnspod update handling, proper certificate selection with ACME, reuse of HTTP client in forward auth, safe handling of missing ECS container info, and edge case for root path rewrite target in Kubernetes.
Added support for wildcard hosts in the ingress provider.
Updated acme/lego to v3.3.0 and fixed multiple bugs in Docker port handling, service definitions, server content‑type detection, and a memory leak in safe.Pool.
Fixed bugs in logs, middleware, and metrics components.
Added numerous features: Consul catalog options/provider, full CRD service kind support, configurable statsd prefix, conditional compression, internal provider, TLS MaxVersion and EC curve preferences, updated Jaeger dependencies.
Fix truncation of keys in logs for proper identification.
Fix bug in logs and middleware handling, including mirroring impact and TLS cert parsing; prevent server from stopping TCP listeners on temporary errors
Fixed multiple bugs across services (acme, healthcheck, middleware, tracing, web UI, logging) and updated dependencies
Fixed multiple bugs across metrics, middleware (stripPrefix, rate limiting, SSE), tracing library upgrade, Docker compose config, and documentation links
Multiple bug fixes across ACME, logs, Kubernetes ingress, middleware, tracing, and server load balancing.
Added precise float weight computation functions for k8s ingress handling.
Fixed multiple bugs across ACME client, Kubernetes ingress, file provider, metrics recorder, and other components
Update compiled with Go 1.13.1 to patch a known vulnerability (CVE).
Compiled with Go 1.12.10, addressing the known Go compiler vulnerability (CVE referenced).
Fix: Prevent stdout from being closed when the accesslog handler shuts down and ensure WriteHeader correctly sends headers and status code.
Introduced a new API security model and contract, removing entrypoint and middleware configuration (breaking change).
Fixed middleware and websocket components
Add Kubernetes Auth.HeaderField support and improve throttling mechanisms
Updated Go runtime to version 1.12.8.
Bug fixes across multiple modules: acme, consulcatalog, Docker API, DynamoDB tag handling, healthcheck weight handling, multi‑port K8s services, log timezone, TLS client header handling, and TLS key usage defaults.