Traefik version lifecycle

tool · Traefik Labs

Current status

supported

Supported version lines, end-of-life status, and latest releases for Traefik — derived from official vendor sources, not third-party EOL aggregators.

Traefik is a cloud-native reverse proxy and load balancer for HTTP, TCP, and UDP with automatic service discovery.

Security: 12 tracked advisories · 1 in CISA KEV. Details below — lifecycle and vulnerability status are separate.

Official site →

Version lines

28

Supported

28

EOL lines

0

Latest stable

3.7.12

2026-08-26

Releases tracked

292

At a glance

Latest release

3.7.12

Line 3.7

Recommended support line

3.7

standard support

Status

STANDARD SUPPORT

Newest supported: 3.7

EOL

Not published

Exact date not officially published

Recommended line: 3.7 (newest supported line with lowest lifecycle risk — not blindly “latest”).

Supported versions

28 currently supported release lines.

Version lineLifecycleLatest releaseReleasedEOLRisk
3.7
standard supportlow
3.7.122026-08-26Not officially publishedlow
3.6
standard supportlow
3.6.252026-07-31Not officially publishedlow
3.5
standard supportlow
3.5.62025-11-07Not officially publishedlow
3.4
standard supportlow
3.4.52025-07-23Not officially publishedlow
3.3
standard supportlow
3.3.72025-05-05Not officially publishedlow
3.2
standard supportlow
3.2.52025-01-07Not officially publishedlow
3.1
standard supportlow
3.1.72024-10-28Not officially publishedlow
3.0
standard supportlow
3.0.42024-07-02Not officially publishedlow
2.11
standard supportlow
2.11.562026-08-26Not officially publishedlow
2.10
standard supportlow
2.10.72023-12-06Not officially publishedlow
2.9
standard supportlow
2.9.102023-04-06Not officially publishedlow
2.8
standard supportlow
2.8.82022-09-30Not officially publishedlow
2.7
standard supportlow
2.7.32022-06-29Not officially publishedlow
2.6
standard supportlow
2.6.72022-05-24Not officially publishedlow
2.5
standard supportlow
2.5.72022-01-20Not officially publishedlow
2.4
standard supportlow
2.4.142021-08-16Not officially publishedlow
2.3
standard supportlow
2.3.72021-01-11Not officially publishedlow
2.2
standard supportlow
2.2.112020-09-07Not officially publishedlow
2.1
standard supportlow
2.1.92020-03-23Not officially publishedlow
2.0
standard supportlow
2.0.72019-12-09Not officially publishedlow
1.7
standard supportlow
1.7.342021-12-10Not officially publishedlow
1.6
standard supportlow
1.6.62018-08-20Not officially publishedlow
1.5
standard supportlow
1.5.42018-03-15Not officially publishedlow
1.4
standard supportlow
1.4.62018-01-02Not officially publishedlow
1.3
standard supportlow
1.3.82017-09-07Not officially publishedlow
1.2
standard supportlow
1.2.32017-04-13Not officially publishedlow
1.1
standard supportlow
1.1.22016-12-15Not officially publishedlow
1.0
standard supportlow
1.0.32016-09-22Not officially publishedlow

Lifecycle overview

Support windows from official lifecycle periods. Empty segments mean no dated period for that phase.

  • 3.7standard support
    standard support
  • 3.6standard support
    standard support
  • 3.5standard support
    standard support
  • 3.4standard support
    standard support
  • 3.3standard support
    standard support
  • 3.2standard support
    standard support
  • 3.1standard support
    standard support
  • 3.0standard support
    standard support
  • 2.11standard support
    standard support
  • 2.10standard support
    standard support
  • 2.9standard support
    standard support
  • 2.8standard support
    standard support
  • 2.7standard support
    standard support
  • 2.6standard support
    standard support
  • 2.5standard support
    standard support
  • 2.4standard support
    standard support

Showing 16 of 28 lines with lifecycle periods. See the directory below for the full list.

Known exploited vulnerabilities

CVE entries that CISA lists in the Known Exploited Vulnerabilities catalogue, including due dates and ransomware use when published. CVSS shown when NVD enrichment is available.

  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    >=4.0,<=4.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; >=3.0.0,<=3.3.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; <1.21.4.3; <2.5.0; >=4,<=4; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
    Fixed in:
    10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 1.21.4.3, 2.5.0, 2.10.5
    Source:
    CISA KEV · Advisory

Known vulnerabilities

Recent OSV.dev advisories mapped to this product. CVSS/CWE from NVD and known-exploited status from CISA KEV when available. CompatHub is not the original vulnerability authority.

Known vulnerabilities
12
Known exploited
1
Highest CVSS
  • CVE-2023-44487Known exploited

    HTTP/2 Rapid Reset Attack Vulnerability

    CISA KEV:
    listed · added 2023-10-10 · due 2023-10-31
    Required action:
    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
    Affected:
    >=4.0,<=4.0; <10.5.3; >=1.5,<2.2.0; >=1.0,<1.0; <9.4.0; >=11.0.0-milestone9,<=11.0.0-milestone9; >=9.0.0,<9.2.3; <1.28.0; <2023-10-08; <2.7.5; >=7.0.0,<7.0.12; >=1.27.0,<=1.27.0; >=3.0.0,<=3.3.0; <2023.10.16.00; >=1.21.0,<1.21.3; <0.17.0; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<1.58.3; >=1.57.0-NA,<=1.57.0-NA; >=1.0-sp2,<1.1; >=1.19.0,<1.19.1; <=2.427; >=12.0.0,<12.0.2; <4.2.2; <3.4.2; <1.22; <1.26.0; >=2.14.1,<=2.14.1; <4.1.100; <1.57.0; >=1.9.5,<=1.25.2; >=20.0.0,<20.8.1; <1.21.4.3; <2.5.0; >=4,<=4; >=8.0,<=8.0; >=3.0.0-beta3,<2.10.5
    Fixed in:
    10.5.3, 2.2.0, 1.0, 9.4.0, 9.2.3, 1.28.0, 2023-10-08, 2.7.5, 7.0.12, 2023.10.16.00, 1.21.3, 0.17.0, 1.58.3, 1.1, 1.19.1, 12.0.2, 4.2.2, 3.4.2, 1.22, 1.26.0, 4.1.100, 1.57.0, 20.8.1, 1.21.4.3, 2.5.0, 2.10.5
    Source:
    CISA KEV · Advisory
  • CVE-2026-71327

    Traefik: Gateway API route identity collision allows cross-namespace backend hijacking

    Affected:
    >=3.7.0,<3.7.10
    Fixed in:
    3.7.10
    Source:
    OSV source · Advisory
  • CVE-2026-71326

    Traefik: BasicAuth singleflight key collision allows authenticated identity spoofing

    Affected:
    >=3.7.0,<3.7.10
    Fixed in:
    3.7.10
    Source:
    OSV source · Advisory
  • CVE-2026-71325

    Traefik: `allowCrossNamespace=false` bypass via `@kubernetescrd` TraefikService backendRef

    Affected:
    >=3.7.0,<3.7.10
    Fixed in:
    3.7.10
    Source:
    OSV source · Advisory
  • CVE-2026-71324

    Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

    Affected:
    >=3.7.0,<3.7.9
    Fixed in:
    3.7.9
    Source:
    OSV source · Advisory
  • CVE-2026-67309

    Traefik v3.7.0 Path Traversal via RewriteTarget Authentication Bypass

    Affected:
    >=3.7.0,<3.7.8
    Fixed in:
    3.7.8
    Source:
    OSV source · Advisory
  • CVE-2026-65602

    Traefik before 3.6.23 IngressRouteTCP ServersTransport Namespace Bypass

    Affected:
    >=3.7.0,<3.7.7
    Fixed in:
    3.7.7
    Source:
    OSV source · Advisory
  • CVE-2026-65601

    Traefik before 3.7.7 Namespace Confusion via HTTPRoute ExtensionRef

    Affected:
    >=3.7.0,<3.7.7
    Fixed in:
    3.7.7
    Source:
    OSV source · Advisory
  • CVE-2026-65600

    Traefik before v2.11.52 Authentication Bypass via ReplacePathRegex

    Affected:
    >=3.7.0,<3.7.7
    Fixed in:
    3.7.7
    Source:
    OSV source · Advisory
  • CVE-2026-54763

    Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

    Affected:
    >=3.7.0,<3.7.6
    Fixed in:
    3.7.6
    Source:
    OSV source · Advisory
  • CVE-2026-54765

    Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes sharing a Service:port

    Affected:
    >=3.7.0,<3.7.6
    Fixed in:
    3.7.6
    Source:
    OSV source · Advisory
  • CVE-2026-54764

    ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

    Affected:
    >=3.7.0,<3.7.6
    Fixed in:
    3.7.6
    Source:
    OSV source · Advisory

Compare versions

Side-by-side view of the most relevant release lines.

3.73.63.53.4
Statusstandard supportstandard supportstandard supportstandard support
Latest3.7.123.6.253.5.63.4.5
Released2026-08-262026-07-312025-11-072025-07-23
EOLNot officially publishedNot officially publishedNot officially publishedNot officially published
Risklowlowlowlow

Recent releases

Latest release date 2026-08-26 · 4 in last 30 days · 26 in last 90 days

Should I upgrade?

Current versions are supported

The preferred supported release line is Traefik 3.7 (standard support).

Data coverage

Version lines
28
Concrete releases
292
Supported lines
28
EOL lines
0
Lifecycle coverage
28/28
EOL coverage
0/28
Provenance coverage
28/28

Data freshness

Last checked = last successful upstream check. Latest source update = when upstream content last changed.

Data last checked
2026-09-01
Latest source update
2026-09-01

Sources

First-party and other registered sources contributing release and lifecycle facts.

Version line directory

Complete navigation into detailed version-line pages.

Currently supported

Version lineStatusLatest releaseReleasedEOL
3.7
standard supportlow
3.7.122026-08-26Not officially published
3.6
standard supportlow
3.6.252026-07-31Not officially published
3.5
standard supportlow
3.5.62025-11-07Not officially published
3.4
standard supportlow
3.4.52025-07-23Not officially published
3.3
standard supportlow
3.3.72025-05-05Not officially published
3.2
standard supportlow
3.2.52025-01-07Not officially published
3.1
standard supportlow
3.1.72024-10-28Not officially published
3.0
standard supportlow
3.0.42024-07-02Not officially published
2.11
standard supportlow
2.11.562026-08-26Not officially published
2.10
standard supportlow
2.10.72023-12-06Not officially published
2.9
standard supportlow
2.9.102023-04-06Not officially published
2.8
standard supportlow
2.8.82022-09-30Not officially published
2.7
standard supportlow
2.7.32022-06-29Not officially published
2.6
standard supportlow
2.6.72022-05-24Not officially published
2.5
standard supportlow
2.5.72022-01-20Not officially published
2.4
standard supportlow
2.4.142021-08-16Not officially published
2.3
standard supportlow
2.3.72021-01-11Not officially published
2.2
standard supportlow
2.2.112020-09-07Not officially published
2.1
standard supportlow
2.1.92020-03-23Not officially published
2.0
standard supportlow
2.0.72019-12-09Not officially published
1.7
standard supportlow
1.7.342021-12-10Not officially published
1.6
standard supportlow
1.6.62018-08-20Not officially published
1.5
standard supportlow
1.5.42018-03-15Not officially published
1.4
standard supportlow
1.4.62018-01-02Not officially published
1.3
standard supportlow
1.3.82017-09-07Not officially published
1.2
standard supportlow
1.2.32017-04-13Not officially published
1.1
standard supportlow
1.1.22016-12-15Not officially published
1.0
standard supportlow
1.0.32016-09-22Not officially published