[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-54386":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-06T08:55:34.825Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":47,"aliases":48,"duplicate_of":9,"upstream":51,"downstream":52,"duplicates":59,"related":60,"reserved_at":9,"published_at":66,"modified_at":67,"state":68,"summary":69,"references_raw":78,"kevs":122,"epss":123,"epss_history":126,"metrics":392,"affected":406},"CVE-2025-54386","Traefik is an HTTP reverse proxy and load balancer. In versions 2.11.27 and below, 3.0.0 through 3.4.4 and 3.5.0-rc1, a path traversal vulnerability was discovered in WASM Traefik’s plugin installation mechanism. By supplying a maliciously crafted ZIP archive containing file paths with ../ sequences, an attacker can overwrite arbitrary files on the system outside of the intended plugin directory. This can lead to remote code execution (RCE), privilege escalation, persistence, or denial of service. This is fixed in versions 2.11.28, 3.4.5 and 3.5.0.",null,[11,40],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-22","Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')","The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.","weakness","Stable","Base","High",[20,24,28,32,36],{"id":21,"name":22,"techniques":23},"CAPEC-126","Path Traversal",[],{"id":25,"name":26,"techniques":27},"CAPEC-64","Using Slashes and URL Encoding Combined to Bypass Validation Logic",[],{"id":29,"name":30,"techniques":31},"CAPEC-76","Manipulating Web Input to File System Calls",[],{"id":33,"name":34,"techniques":35},"CAPEC-78","Using Escaped Slashes in Alternate Encoding",[],{"id":37,"name":38,"techniques":39},"CAPEC-79","Using Slashes in Alternate Encoding",[],{"_key":41,"id":41,"name":42,"description":43,"type":15,"status":44,"abstraction":45,"likelihood_of_exploit":9,"capec":46},"CWE-30","Path Traversal: '\\dir\\..\\filename'","The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\\dir\\..\\filename' (leading backslash dot dot) sequences that can resolve to a location that is outside of that directory.","Draft","Variant",[],[],[49,50],"GHSA-q6gg-9f92-r9wg","GO-2025-3835",[],[53,55,57],{"_key":54},"SUSE-SU-2025:02912-1",{"_key":56},"OPENSUSE-SU-2025:15434-1",{"_key":58},"OPENSUSE-SU-2026:10143-1",[],[61,62,63,64],{"_key":54},{"_key":56},{"_key":58},{"_key":65},"CGA-G885-96HV-5638","2025-08-01T23:32:21.747Z","2025-08-04T15:28:06.189Z","Analyzed",{"cisa_kev":70,"cisa_ransomware":70,"cisa_vendor":9,"epss_severity":71,"epss_score":72,"severity":73,"severity_score":74,"severity_version":75,"severity_source":76,"severity_vector":77,"severity_status":68},false,"low",0.03359,"critical",9.8,"v3.1","nvd","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",[79,89,95,99,104,108,113,117],{"url":80,"sources":81,"tags":84},"https://github.com/traefik/traefik/security/advisories/GHSA-q6gg-9f92-r9wg",[82,76,83],"cve.org","osv_go",[85,86,87,88],"X Refsource CONFIRM","Vendor Advisory","WEB","Advisory",{"url":90,"sources":91,"tags":92},"https://github.com/traefik/plugin-service/pull/71",[82,76,83],[93,94,87],"X Refsource MISC","Patch",{"url":96,"sources":97,"tags":98},"https://github.com/traefik/plugin-service/pull/72",[82,76,83],[93,94,87],{"url":100,"sources":101,"tags":102},"https://github.com/traefik/traefik/pull/11911",[82,76,83],[93,94,87,103],"FIX",{"url":105,"sources":106,"tags":107},"https://github.com/traefik/traefik/commit/5ef853a0c53068f69a6c229a5815a0dc6e0a8800",[82,76,83],[93,94,87,103],{"url":109,"sources":110,"tags":111},"https://github.com/traefik/traefik/releases/tag/v2.11.28",[82,76,83],[93,112,87],"Release Notes",{"url":114,"sources":115,"tags":116},"https://nvd.nist.gov/vuln/detail/CVE-2025-54386",[83],[88],{"url":118,"sources":119,"tags":120},"https://github.com/traefik/traefik",[83],[121],"PACKAGE",[],{"date":124,"score":72,"percentile":125},"2026-06-05",0.87581,[127,131,134,137,140,142,145,148,151,154,157,160,163,165,168,172,175,178,181,183,185,188,191,194,198,201,204,207,211,214,216,219,222,225,228,231,234,237,240,243,245,248,251,254,257,260,263,266,268,271,273,276,279,282,285,289,293,296,299,302,305,308,310,313,316,319,322,326,328,331,334,337,340,343,346,349,352,355,357,360,363,366,369,372,374,377,380,383,386,389],{"date":128,"score":129,"percentile":130},"2025-11-04",0.00931,0.75351,{"date":132,"score":129,"percentile":133},"2025-11-05",0.75346,{"date":135,"score":129,"percentile":136},"2025-11-06",0.75343,{"date":138,"score":129,"percentile":139},"2025-11-07",0.75359,{"date":141,"score":129,"percentile":139},"2025-11-08",{"date":143,"score":129,"percentile":144},"2025-11-09",0.75356,{"date":146,"score":129,"percentile":147},"2025-11-10",0.75345,{"date":149,"score":129,"percentile":150},"2025-11-11",0.75348,{"date":152,"score":129,"percentile":153},"2025-11-12",0.75367,{"date":155,"score":129,"percentile":156},"2025-11-13",0.75373,{"date":158,"score":129,"percentile":159},"2025-11-14",0.75378,{"date":161,"score":129,"percentile":162},"2025-11-15",0.75376,{"date":164,"score":129,"percentile":162},"2025-11-16",{"date":166,"score":129,"percentile":167},"2025-11-17",0.75366,{"date":169,"score":170,"percentile":171},"2025-11-18",0.0126,0.77637,{"date":173,"score":170,"percentile":174},"2025-11-19",0.77645,{"date":176,"score":170,"percentile":177},"2025-11-20",0.77653,{"date":179,"score":129,"percentile":180},"2025-11-21",0.75392,{"date":182,"score":129,"percentile":180},"2025-11-22",{"date":184,"score":129,"percentile":162},"2025-11-23",{"date":186,"score":129,"percentile":187},"2025-11-24",0.75374,{"date":189,"score":129,"percentile":190},"2025-11-25",0.75377,{"date":192,"score":129,"percentile":193},"2025-11-26",0.75386,{"date":195,"score":196,"percentile":197},"2025-11-27",0.01167,0.78018,{"date":199,"score":196,"percentile":200},"2025-11-28",0.78009,{"date":202,"score":196,"percentile":203},"2025-11-29",0.78016,{"date":205,"score":196,"percentile":206},"2025-11-30",0.78014,{"date":208,"score":209,"percentile":210},"2025-12-01",0.01293,0.79159,{"date":212,"score":209,"percentile":213},"2025-12-02",0.79161,{"date":215,"score":209,"percentile":213},"2025-12-03",{"date":217,"score":209,"percentile":218},"2025-12-04",0.79067,{"date":220,"score":209,"percentile":221},"2025-12-05",0.79071,{"date":223,"score":209,"percentile":224},"2025-12-06",0.79073,{"date":226,"score":209,"percentile":227},"2025-12-07",0.79074,{"date":229,"score":209,"percentile":230},"2025-12-08",0.79078,{"date":232,"score":209,"percentile":233},"2025-12-09",0.79094,{"date":235,"score":209,"percentile":236},"2025-12-10",0.79116,{"date":238,"score":209,"percentile":239},"2025-12-11",0.7913,{"date":241,"score":209,"percentile":242},"2025-12-12",0.7915,{"date":244,"score":209,"percentile":242},"2025-12-13",{"date":246,"score":209,"percentile":247},"2025-12-14",0.79147,{"date":249,"score":209,"percentile":250},"2025-12-15",0.79148,{"date":252,"score":209,"percentile":253},"2025-12-16",0.79158,{"date":255,"score":209,"percentile":256},"2025-12-17",0.79165,{"date":258,"score":209,"percentile":259},"2025-12-18",0.79185,{"date":261,"score":209,"percentile":262},"2025-12-19",0.79196,{"date":264,"score":209,"percentile":265},"2025-12-20",0.79191,{"date":267,"score":209,"percentile":259},"2025-12-21",{"date":269,"score":209,"percentile":270},"2025-12-22",0.79187,{"date":272,"score":209,"percentile":270},"2025-12-23",{"date":274,"score":209,"percentile":275},"2025-12-24",0.79202,{"date":277,"score":209,"percentile":278},"2025-12-25",0.79221,{"date":280,"score":209,"percentile":281},"2025-12-26",0.79218,{"date":283,"score":209,"percentile":284},"2025-12-27",0.79268,{"date":286,"score":287,"percentile":288},"2025-12-28",0.00708,0.71605,{"date":290,"score":291,"percentile":292},"2025-12-29",0.00568,0.67823,{"date":294,"score":291,"percentile":295},"2025-12-30",0.67837,{"date":297,"score":291,"percentile":298},"2025-12-31",0.67855,{"date":300,"score":291,"percentile":301},"2026-01-01",0.68031,{"date":303,"score":291,"percentile":304},"2026-01-02",0.68018,{"date":306,"score":291,"percentile":307},"2026-01-03",0.68019,{"date":309,"score":291,"percentile":298},"2026-01-04",{"date":311,"score":291,"percentile":312},"2026-01-05",0.67843,{"date":314,"score":291,"percentile":315},"2026-01-06",0.67854,{"date":317,"score":291,"percentile":318},"2026-01-07",0.67873,{"date":320,"score":291,"percentile":321},"2026-01-08",0.67888,{"date":323,"score":324,"percentile":325},"2026-01-09",0.00661,0.7059,{"date":327,"score":324,"percentile":325},"2026-01-10",{"date":329,"score":324,"percentile":330},"2026-01-11",0.70585,{"date":332,"score":324,"percentile":333},"2026-01-12",0.70574,{"date":335,"score":324,"percentile":336},"2026-01-13",0.70571,{"date":338,"score":324,"percentile":339},"2026-01-14",0.70597,{"date":341,"score":324,"percentile":342},"2026-01-15",0.70604,{"date":344,"score":324,"percentile":345},"2026-01-16",0.70622,{"date":347,"score":324,"percentile":348},"2026-01-17",0.70616,{"date":350,"score":324,"percentile":351},"2026-01-18",0.70598,{"date":353,"score":324,"percentile":354},"2026-01-19",0.70589,{"date":356,"score":324,"percentile":351},"2026-01-20",{"date":358,"score":324,"percentile":359},"2026-01-21",0.70601,{"date":361,"score":324,"percentile":362},"2026-01-22",0.70614,{"date":364,"score":324,"percentile":365},"2026-01-23",0.70647,{"date":367,"score":324,"percentile":368},"2026-01-24",0.70652,{"date":370,"score":324,"percentile":371},"2026-01-25",0.70626,{"date":373,"score":324,"percentile":345},"2026-01-26",{"date":375,"score":324,"percentile":376},"2026-01-27",0.70624,{"date":378,"score":324,"percentile":379},"2026-01-28",0.7064,{"date":381,"score":324,"percentile":382},"2026-01-29",0.70637,{"date":384,"score":324,"percentile":385},"2026-01-30",0.70646,{"date":387,"score":324,"percentile":388},"2026-01-31",0.70651,{"date":390,"score":324,"percentile":391},"2026-02-01",0.70783,[393,398,404],{"source":82,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":394},{"baseScore":395,"baseSeverity":396,"vectorString":397,"impactScore":9,"exploitabilityScore":9},7.3,"HIGH","CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L",{"source":76,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":399,"cvss_v4_0":402},{"baseScore":74,"baseSeverity":400,"vectorString":77,"impactScore":74,"exploitabilityScore":401},"CRITICAL",10,{"baseScore":395,"baseSeverity":396,"vectorString":403,"impactScore":9,"exploitabilityScore":9},"CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",{"source":83,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":405},{"baseScore":395,"baseSeverity":9,"vectorString":397,"impactScore":9,"exploitabilityScore":9},[407,418,426,438],{"ecosystem":408,"name":409,"vendor":410,"product":411,"cpe_part":9,"purl_type":412,"purl_namespace":410,"purl_name":411,"source":9,"versions":413},"Go","github.com/traefik/traefik","github.com/traefik","traefik","golang",[414],{"version":415,"is_range":416,"range_type":417,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"all",true,"semver",{"ecosystem":408,"name":419,"vendor":409,"product":420,"cpe_part":9,"purl_type":412,"purl_namespace":409,"purl_name":420,"source":9,"versions":421},"github.com/traefik/traefik/v2","v2",[422],{"version":423,"is_range":416,"range_type":417,"version_start":9,"version_start_type":9,"version_end":424,"version_end_type":425,"fixed_in":9},"lt2_11_28","2.11.28","excluding",{"ecosystem":408,"name":427,"vendor":409,"product":428,"cpe_part":9,"purl_type":412,"purl_namespace":409,"purl_name":428,"source":9,"versions":429},"github.com/traefik/traefik/v3","v3",[430,433],{"version":431,"is_range":416,"range_type":417,"version_start":9,"version_start_type":9,"version_end":432,"version_end_type":425,"fixed_in":9},"lt3_4_5","3.4.5",{"version":434,"is_range":416,"range_type":417,"version_start":435,"version_start_type":436,"version_end":437,"version_end_type":425,"fixed_in":9},"gte3_5_0_rc1_lt3_5_0","3.5.0-rc1","including","3.5.0",{"ecosystem":9,"name":411,"vendor":411,"product":411,"cpe_part":439,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":440},"a",[441,443,445,448,452,456,457,459],{"version":442,"is_range":416,"range_type":82,"version_start":9,"version_start_type":9,"version_end":424,"version_end_type":425,"fixed_in":9},"\u003C= 2.11.27, \u003C 2.11.28",{"version":444,"is_range":416,"range_type":82,"version_start":9,"version_start_type":9,"version_end":432,"version_end_type":425,"fixed_in":9},"\u003C= 3.0.0, \u003C 3.4.5",{"version":446,"is_range":416,"range_type":82,"version_start":435,"version_start_type":436,"version_end":447,"version_end_type":425,"fixed_in":9},">= 3.5.0-rc1, \u003C 3.5.0-rc2","3.5.0-rc2",{"version":449,"is_range":416,"range_type":450,"version_start":9,"version_start_type":9,"version_end":451,"version_end_type":425,"fixed_in":9},"lt2.11.7","cpe","2.11.7",{"version":453,"is_range":416,"range_type":450,"version_start":454,"version_start_type":436,"version_end":455,"version_end_type":425,"fixed_in":9},"gte3.0.0_lt3.4.4","3.0.0","3.4.4",{"version":437,"is_range":70,"range_type":450,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},{"version":458,"is_range":70,"range_type":450,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.5.0:rc1",{"version":460,"is_range":70,"range_type":450,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"3.5.0:rc2"]