Traefik Release Notes
42 release notes curated from 1 source by the Releasebot Team. Last updated: Sep 4, 2026
- Sep 4, 2026
- Date parsed from source:Sep 4, 2026
- First seen by Releasebot:Sep 4, 2026
v3.7.13
Traefik fixes ACME DNS challenge handling, HTTP/3, Kubernetes ingress-nginx sticky sessions and ssl-passthrough redirects, server request forwarding, middleware auth and custom errors, plus logging, TLS, WebUI and docs updates.
Important: Please read the migration guide.
Bug fixes
- [acme] Bump github.com/go-acme/lego/v5 to v5.4.1 (#13759 @ldez)
- [acme] Disable recursive nss propagation by default for DNS challenge (#13830 @rtribotte)
- [acme] Do not require recursive nameservers propagation by default for the DNS-01 challenge (#13710 @amazon7737)
- [acme, tls] Ignore negated matchers when parsing rule domains (#13725 @rtribotte)
- [consulcatalog, nomad] Build a collision-free item key in the Consul Catalog and Nomad providers (#13741 @rtribotte)
- [http3] Dedicate a transport per HTTP/3 client connection (#13812 @sdelicata)
- [k8s/ingress-nginx] Fix sticky cookie expiration per request (#13496 @makaiver)
- [k8s/ingress-nginx] Create HTTP redirect router for ssl-passthrough with force-ssl-redirect (#13457 @mmatur)
- [k8s/ingress-nginx] Preserve leading dot in sticky session cookie Domain attribute (#13456 @mmatur)
- [logs, middleware] Set access log entry level and time before formatting the OTLP body (#13767 @emilevauge)
- [logs, tls, k8s/crd] Downgrade default TLS resources namespace mismatch log to warning (#13780 @lazerg)
- [middleware] Fix {url} placeholder in customErrors middleware now includes correct scheme (#13320 @AnouarMohamed)
- [middleware, authentication] Prevent user enumeration through the basic auth singleflight key (#13816 @sdelicata)
- [server] Build the configuration copy once per change (#13746 @jspdown)
- [server] Do not forward h2c upgrade headers to the backend (#13797 @sdelicata)
- [server] Deny request with an opaque request target (#13796 @sdelicata)
- [server] Do not forward request trailer values to the backend (#13822 @rtribotte)
- [server] Bump github.com/quic-go/quic-go to v0.62.0 (#13807 @Nelwhix)
- [tls] Redact duplicate TLS certificates in provider merge logs (#13548 @xsergos)
- [webui] Fix displayed number on details pages (#13779 @gndz07)
Documentation
- [k8s] Add warning about Ingress API frozen state (#13783 @jnoordsij)
- [k8s] Remove namespace reference for providers.kubernetesGateway.labelSelector (#13790 @jnoordsij)
- [k8s/crd] Fix broken redirect for the Kubernetes CRD reference docs (#13811 @thev1ndu)
- Tell scanning agents to read the security policy and decisions pages (#13753 @emilevauge)
- Sep 4, 2026
- Date parsed from source:Sep 4, 2026
- First seen by Releasebot:Sep 4, 2026
v2.11.57
Traefik ships bug fixes for ACME DNS challenge, HTTP/3 transport handling, and server request handling.
Important: Please read the migration guide.
Bug fixes:
- [acme] Disable recursive nss propagation by default for DNS challenge (#13830 @rtribotte)
- [http3] Dedicate a transport per HTTP/3 client connection (#13812 @sdelicata)
- [server] Deny request with an opaque request target (#13796 @sdelicata)
- [server] Do not forward h2c upgrade headers to the backend (#13797 @sdelicata)
All of your release notes in one feed
Join Releasebot and get updates from Traefik and hundreds of other software products.
- Aug 27, 2026
- Date parsed from source:Aug 27, 2026
- First seen by Releasebot:Aug 26, 2026
- Modified by Releasebot:Aug 27, 2026
v3.7.12
Traefik ships security fixes and bug improvements across HTTP/3, Kubernetes, file provider, fastproxy, TCP and UDP, with updated docs and a migration guide. It also tightens timeout handling, fixes redirect and TLS edge cases, and bumps key dependencies.
Important: Please read the migration guide.
CVE fixed:
Advisory GHSA-cjr6-pf59-jq29
Advisory GHSA-7ghq-v6jf-g56c
Advisory GHSA-rf44-j88r-hh8c
Bug fixes:
- [fastproxy] Bump github.com/valyala/fasthttp to v1.73.0 (#13769 @mmatur)
- [file] Include the filename in file provider configuration errors (#13527 @lazerg)
- [http3] Apply read timeout, idle timeout, and max header bytes for HTTP/3 (#13717 @gndz07)
- [k8s] Fix typos in docs and an OCSP log message (#13722 @MsfPablo)
- [k8s, k8s/ingress-nginx] Fix redirect www host with a non-numeric port (#13708 @mmatur)
- [k8s/ingress-nginx] Fix TLS option name collision across namespaces in the ingress-nginx provider (#13721 @gndz07)
- [server] Add an entry point option to handle request headers with aliasing names (#13720 @rtribotte)
- [tcp, udp] Reject negative weights in TCP and UDP weighted services (#13749 @rtribotte)
- Bump etcd client modules to v3.5.33 (#13756 @mmatur)
Documentation:
- [k8s] Update redirections block reference in basic.md (#13723 @Larzenegger)
- [k8s] Fix formatting in Kubernetes setup guide (#13742 @stefkiourk)
- [security] Document the security threat model and settled security decisions (#13740 @emilevauge)
- [service] Clarify ServersTransport behavior for the errors middleware in Kubernetes (#13531 @lazerg)
- Fix v3.7.11 migration guide (#13730 @gndz07)
- Move Jean-Baptiste Doumenjou and Mathieu Lonjaret to past maintainers (#13736 @emilevauge)
- Reduce SECURITY.md to a pointer to the security documentation (#13732 @emilevauge)
- Update end of support dates (#13712 @nmengin)
- Aug 27, 2026
- Date parsed from source:Aug 27, 2026
- First seen by Releasebot:Aug 26, 2026
- Modified by Releasebot:Aug 27, 2026
v2.11.56
Traefik fixes CVEs and strengthens HTTP/3, server headers, and TCP and UDP service handling.
Important: Please read the migration guide.
CVE fixed:
Advisory GHSA-7ghq-v6jf-g56c
Advisory GHSA-rf44-j88r-hh8c
Bug fixes:
- [http3] Apply read timeout, idle timeout, and max header bytes for HTTP/3 (#13717 @gndz07)
- [server] Add an entry point option to handle request headers with aliasing names (#13720 @rtribotte)
- [tcp, udp] Reject negative weights in TCP and UDP weighted services (#13749 @rtribotte)
- Bump etcd client modules to v3.5.33 (#13756 @mmatur)
- Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 19, 2026
- Modified by Releasebot:Aug 21, 2026
v3.7.11
Traefik ships security fixes for multiple CVEs and improves Kubernetes routing, CRD naming, Gateway API behavior, ingress-nginx handling, and TLS options. The release also updates HTTP/3 dependencies and refreshes documentation across key areas.
Important: Please read the migration guide.
CVE fixed:
- Advisory GHSA-5w68-77r2-r64c
- Advisory GHSA-g55h-rg46-x9c5
- Advisory GHSA-j994-9gqj-9hwq
- Advisory GHSA-m6wx-622r-48r9
Bug fixes:
- [fastproxy] Reject out-of-range status codes from backends when using FastProxy (#13635 @gndz07)
- [http3] Bump github.com/quic-go/quic-go to v0.61.0 (#13688 @jnoordsij)
- [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider (#13656 @rtribotte)
- [k8s/crd] Add an option to restrict the namespace of the default TLS resources (#13665 @rtribotte)
- [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider (#13668 @rtribotte)
- [k8s/crd] Name failover generated services after the referenced Kubernetes Service (#13677 @rtribotte)
- [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider (#13689 @gndz07)
- [k8s/gatewayapi] Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect (#13641 @gndz07)
- [k8s/gatewayapi] Fix Gateway API router rules (#13645 @rtribotte)
- [k8s/ingress-nginx] Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider (#13638 @gndz07)
- [k8s/ingress-nginx] Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend (#13575 @rtribotte)
- [k8s/ingress-nginx] Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider (#13629 @gndz07)
- [k8s/ingress] Enforce crossProviderNamespace for Kubernetes Ingress service middleware (#13670 @gndz07)
- [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 (#13636 @kevinpollet)
- [tls] Add an option to disable the fallback to the default TLS options (#13639 @rtribotte)
- Bump golang.org/x dependencies (#13699 @mmatur)
Documentation:
- [accesslogs] Clarify OriginStatus and DownstreamStatus in access logs documentation (#13609 @rtribotte)
- [api] Fix doubled word in API/dashboard reference docs (#13663 @latent-9)
- [docker] Remove :ro from docker.sock (#12656 @bluepuma77)
- [k8s/gatewayapi] Clarify v3.7.10 migration guide for Gateway API 1.6.1 (#13628 @rtribotte)
- [k8s/gatewayapi] Document the Experimental Channel CRDs requirement of the Kubernetes Gateway provider (#13634 @rtribotte)
- [k8s/ingress-nginx] Docs: Update supported server snippet directives (#13687 @rtsui-harmonicinc)
- [middleware] Add rejectStatusCode to the ipAllowList middleware configuration example (#13664 @amazon7737)
- [middleware] Mark the errors middleware service option as required (#13684 @lazerg)
- [tls] Document the TLS options conflict resolution (#13640 @rtribotte)
- [tls] Clarify router TLS replaces entrypoint TLS (#13630 @sornapudisuresh)
- Document Redis keyspace notifications requirement (#13691 @omkar619-dev)
- Remove retired Go Report Card badge (#13637 @yardenshoham)
- Restore the systemd socket activation documentation (#13701 @lazerg)
- Update version support policy starting with v3.6 (#13627 @nmengin)
Similar to Traefik with recent updates:
- Ubiquiti release notes914 release notes · Latest Sep 5, 2026
- Perplexity release notes30 release notes · Latest Aug 24, 2026
- Tailscale release notes126 release notes · Latest Aug 26, 2026
- Smokeball release notes144 release notes · Latest Sep 4, 2026
- Salesforce release notes71 release notes · Latest Sep 1, 2026
- Microsoft release notes820 release notes · Latest Sep 4, 2026
- Aug 21, 2026
- Date parsed from source:Aug 21, 2026
- First seen by Releasebot:Aug 19, 2026
- Modified by Releasebot:Aug 21, 2026
v2.11.55
Traefik releases a security and stability update with CVE fixes, safer Kubernetes CRD naming and namespace controls, Gateway API router rule fixes, and a new option to disable fallback to default TLS options.
Important: Please read the migration guide.
CVE fixed
- Advisory GHSA-5w68-77r2-r64c
- Advisory GHSA-g55h-rg46-x9c5
Bug fixes
- [k8s/crd] Prevent generated name collisions in the Kubernetes CRD provider (#13656 @rtribotte)
- [k8s/crd] Add an option to restrict the namespace of the default TLS resources (#13665 @rtribotte)
- [k8s/crd] Scope generated Kubernetes Service names to their parent in the CRD provider (#13668 @rtribotte)
- [k8s/crd] Add safe naming option to avoid collisions for Kubernetes CRD provider (#13689 @gndz07)
- [k8s/gatewayapi] Fix Gateway API router rules (#13645 @rtribotte)
- [middleware, authentication] Bump github.com/containous/go-http-auth to b975dcaa8c48 (#13636 @kevinpollet)
- [tls] Add an option to disable the fallback to the default TLS options (#13639 @rtribotte)
- Bump golang.org/x dependencies (#13699 @mmatur)
- Aug 18, 2026
- Date parsed from source:Aug 18, 2026
- First seen by Releasebot:Aug 18, 2026
- Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 1, 2026
- Modified by Releasebot:Aug 4, 2026
v3.7.10
Traefik fixes multiple CVEs and delivers bug fixes across authentication, Kubernetes Gateway API and CRD providers, tracing, and ACME, while also updating key dependencies and clarifying ingress-nginx docs.
CVE fixed
Advisory GHSA-fgjj-px3w-67xx
Advisory GHSA-62fc-8686-hfmq
Advisory GHSA-6765-c87h-8mrf
Bug fixes
- [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 (#13547 @ldez)
- [middleware, authentication] Fix auth singleflight key collision (#13572 @mmatur)
- [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider (#13580 @gndz07)
- [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 (#13530 @kevinpollet)
- Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 (#13574 @mmatur)
- [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider (#13573 @gndz07)
- [middleware] Bump github.com/klauspost/compress to v1.18.7 (#13587 @mmatur)
- [k8s/gatewayapi] Bump sigs.k8s.io/gateway-api to v1.6.1 (#13589 @rtribotte)
Documentation
- [k8s/ingress-nginx] Clarify auth-url/rewrite-target interaction on ingress-nginx provider (#13607 @gndz07)
- Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 1, 2026
- Modified by Releasebot:Aug 4, 2026
v3.6.25
Traefik fixes CVEs and polishes core routing and Kubernetes support with authentication, Gateway API, CRD, tracing, and ACME updates plus several dependency bumps.
CVE fixed
Advisory GHSA-fgjj-px3w-67xx
Advisory GHSA-62fc-8686-hfmq
Advisory GHSA-6765-c87h-8mrf
Bug fixes
- [acme] Bump github.com/go-acme/lego/v5 to v5.3.1 (#13547 @ldez)
- [middleware, authentication] Fix auth singleflight key collision (#13572 @mmatur)
- [k8s/gatewayapi] Avoid router name collisions in Kubernetes Gateway API provider (#13580 @gndz07)
- [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 (#13530 @kevinpollet)
- Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 (#13574 @mmatur)
- [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider (#13573 @gndz07)
- [middleware] Bump github.com/klauspost/compress to v1.18.7 (#13587 @mmatur)
- Aug 3, 2026
- Date parsed from source:Aug 3, 2026
- First seen by Releasebot:Aug 1, 2026
- Modified by Releasebot:Aug 4, 2026
v2.11.54
Traefik fixes a CVE and ships bug fixes across tracing, Kubernetes CRD, and dependency updates.
CVE fixed:
Advisory GHSA-62fc-8686-hfmq
Bug fixes:
- [tracing] Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 (#13530 @kevinpollet)
- Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 (#13574 @mmatur)
- [k8s/crd] Fix cross-namespace service reference check in Kubernetes CRD provider (#13573 @gndz07)
- [middleware] Bump github.com/klauspost/compress to v1.18.7 (#13587 @mmatur)
- Jul 27, 2026
- Date parsed from source:Jul 27, 2026
- First seen by Releasebot:Jul 25, 2026
- Modified by Releasebot:Jul 28, 2026
v3.7.9
Traefik releases a security and bugfix update with a CVE fix, improved CONNECT request handling, an Ingress NGINX redirect fix, Zstd support disabled in the gzhttp wrapper, and updated migration notes for Gateway API and CONNECT requests.
Important: Please read the migration guide.
CVE fixed:
Advisory GHSA-3ccp-42pg-hgv6
Bug fixes:
- [k8s/ingress-nginx] Fix redirect with use-regex in IngressNGINX provider (#13476 @AmariahAK)
- [middleware] Disable Zstd support in the gzhttp wrapper (#13533 @kevinpollet)
- [server] Defer the CONNECT payload until the backend accepts the tunnel (#13542 @sdelicata)
- [server] Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy (#13543 @sdelicata)
- [server] Bump google.golang.org/grpc to v1.82.1 (#13551 @piscue)
- [server] Do not add back CONNECT requests to the pool (#13556 @kevinpollet)
Documentation:
- [k8s/gatewayapi] Document Gateway API generated service names change in the migration guide (#13541 @rtribotte)
- [k8s/ingress-nginx] Fix typo in nginx annotation proxy-buffer-numbers (#13545 @fischerman)
- Add a migration note for CONNECT requests (#13554 @kevinpollet)
- Jul 27, 2026
- Date parsed from source:Jul 27, 2026
- First seen by Releasebot:Jul 25, 2026
- Modified by Releasebot:Jul 28, 2026
v3.6.24
Traefik ships a bug fix and security-focused release with a CVE patch, CRD updates, CONNECT handling fixes, logging cleanup, gRPC upgrade, and documentation updates including a migration note.
Important
Please read the migration guide.
CVE fixed
Advisory GHSA-3ccp-42pg-hgv6
Bug fixes
- [middleware, k8s/crd] Add missing ErrorRequestHeaders field to CRDs (#13498 @kevinpollet)
- [logs] Remove unrelated error from nonexistent cert resolver log (#13469 @ArthurHlt)
- [middleware] Disable Zstd support in the gzhttp wrapper (#13533 @kevinpollet)
- [server] Defer the CONNECT payload until the backend accepts the tunnel (#13542 @sdelicata)
- [server] Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy (#13543 @sdelicata)
- [server] Bump google.golang.org/grpc to v1.82.1 (#13551 @piscue)
- [server] Do not add back CONNECT requests to the pool (#13556 @kevinpollet)
Documentation
- [k8s] Align certificateRef and indicate ports (#13473 @veenoise)
- [rules] Fix syntax notes in routing rule documentation (#13501 @stevenlele)
- Add a migration note for CONNECT requests (#13554 @kevinpollet)
- Jul 27, 2026
- Date parsed from source:Jul 27, 2026
- First seen by Releasebot:Jul 25, 2026
- Modified by Releasebot:Jul 28, 2026
v2.11.53
Traefik fixes a CVE and improves CONNECT handling with CRD updates, backend tunnel handling, and migration guidance.
Important: Please read the migration guide.
CVE fixed:
Advisory GHSA-3ccp-42pg-hgv6
Bug fixes:
- [middleware, k8s/crd] Add missing ErrorRequestHeaders field to CRDs (#13498 @kevinpollet)
- [server] Defer the CONNECT payload until the backend accepts the tunnel (#13542 @sdelicata)
- [server] Bump google.golang.org/grpc to v1.82.1 (#13551 @piscue)
- [server] Do not add back CONNECT requests to the pool (#13556 @kevinpollet)
Documentation:
Add a migration note for CONNECT requests (#13554 @kevinpollet)
Original source - Jul 16, 2026
- Date parsed from source:Jul 16, 2026
- First seen by Releasebot:Jul 16, 2026
- Modified by Releasebot:Jul 17, 2026
v3.7.8
Traefik fixes a CVE and tightens Kubernetes and middleware behavior with CRD updates, ingress-nginx target sanitization, cleaner logs, and a retry middleware panic fix, while also refreshing related documentation.
CVE fixed
Advisory GHSA-8rxv-jg7p-wvg3
Bug fixes
- [middleware, k8s/crd] Add missing ErrorRequestHeaders field to CRDs (#13498 @kevinpollet)
- [k8s/ingress-nginx] Sanitize rewritten target on ingress-nginx provider (#13506 @gndz07)
- [logs] Remove unrelated error from nonexistent cert resolver log (#13469 @ArthurHlt)
- [middleware] Fix panic in retry middleware with Websockets (#13520 @juliens)
Documentation
- [k8s] Align certificateRef and indicate ports (#13473 @veenoise)
- [rules] Fix syntax notes in routing rule documentation (#13501 @stevenlele)
- [k8s/crd] Fix duplicated options table in ServersTransport CRD reference (#13518 @rachana5)
- Jul 9, 2026
- Date parsed from source:Jul 9, 2026
- First seen by Releasebot:Jul 10, 2026
v3.7.7
Traefik releases a security-focused update with CVE fixes, a migration guide update, and multiple bug fixes across middleware, Kubernetes, ACME, OpenTelemetry, and routing. It also improves documentation and clarifies buffering and dashboard redirection behavior.
Important: Please read the migration guide.
CVE fixed
Advisory GHSA-cxjq-mrr5-89rv
Advisory GHSA-42cj-m3vj-89wv
Advisory GHSA-qq9q-x9w4-chhj
Bug fixes
- [middleware, k8s/ingress-nginx] Add app-root middleware with nginx variable interpolation (#13398 @dfeinblatt)
- [rules] Fix consistency between HostSNI() and Host() (#13460 @juliens)
- [k8s, k8s/gatewayapi] Fix ExtensionRef filters on backendRefs to resolve against the HTTPRoute namespace (#13462 @gndz07)
- [middleware] Fix handle empty unknown-length bodies in mirroring (#13399 @amazon7737)
- [k8s/crd] Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider (#13458 @gndz07)
- [middleware] Sanitize replaced path in ReplacePathRegex middleware (#13466 @kevinpollet)
- [acme] Bump software.sslmate.com/src/go-pkcs12 to v0.7.3 (#13477 @rtribotte)
- [otel] Bump go.opentelemetry.io/otel to v1.44.0 (#13478 @rtribotte)
- [k8s] Fix panic when endpointslice port value or name is nil (#13481 @kevinpollet)
Documentation
- Fix version in migration guide (#13434 @kevinpollet)
- Fix changelog v2.11.51 (#13430 @mmatur)
- Add v3.7 to supported version docs (#13118 @jnoordsij)
- Fix some function names in comments (#13443 @blackflytech)
- Add @nandorKollar as a current maintainer (#13451 @emilevauge)
- Add @amazon7737 as a current maintainer (#13450 @emilevauge)
- [middleware] Clarify buffering middleware defaults (#13401 @amazon7737)
- Fix grammar in TLS, TCP service, and routing reference docs (#13461 @almightymoon)
- Fix X-Forwarded-Prefix documentation for dashboard redirection (#13472 @kevinpollet)
Curated by the Releasebot team
Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.
Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.