# Traefik: what changed from 2 to 3 - Product: Traefik (https://whatsnew.fyi/product/traefik) - Vendor: Traefik Labs - Range: changelog entries numbered after v2.11.57 up to and including v3.7.13, stable releases only - Entries below: 10 releases (newest first) - Resolved: 2 is v2.11.57 and 3 is v3.7.13, the newest stable release of each major we track - Carrying security changes: 9 · CVEs mentioned: 0 · Mentioning breaking changes: 0 · Removing or deprecating something: 0 - Page: https://whatsnew.fyi/product/traefik/compare/2...3 What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## What changed (81 changes, grouped by kind) ### Added #### v3.7.12 (2026-08-26) - Add an entry point option to handle request headers with aliasing names #### v3.7.11 (2026-08-19) - Add an option to restrict the namespace of the default TLS resources - Add safe naming option to avoid collisions for Kubernetes CRD provider - Add an option to disable the fallback to the default TLS options ### Changed #### v3.7.12 (2026-08-26) - Bump github.com/valyala/fasthttp to v1.73.0 - Bump etcd client modules to v3.5.33 #### v3.7.11 (2026-08-19) - Bump github.com/quic-go/quic-go to v0.61.0 - Bump github.com/containous/go-http-auth to b975dcaa8c48 - Bump golang.org/x dependencies #### v3.7.9 (2026-07-24) - Bump google.golang.org/grpc to v1.82.1 (also in v3.6.24) #### v3.7.7 (2026-07-08) - Bump software.sslmate.com/src/go-pkcs12 to v0.7.3 - Bump go.opentelemetry.io/otel to v1.44.0 ### Fixed #### v3.7.13 (2026-09-04) - Disable recursive nss propagation by default for DNS challenge - Ignore negated matchers when parsing rule domains - Build a collision-free item key in the Consul Catalog and Nomad providers - Dedicate a transport per HTTP/3 client connection - Fix sticky cookie expiration per request - Create HTTP redirect router for ssl-passthrough with force-ssl-redirect - Preserve leading dot in sticky session cookie Domain attribute - Set access log entry level and time before formatting the OTLP body - Downgrade default TLS resources namespace mismatch log to warning - Fix {url} placeholder in customErrors middleware now includes correct scheme - Prevent user enumeration through the basic auth singleflight key - Build the configuration copy once per change - Do not forward h2c upgrade headers to the backend - Deny request with an opaque request target - Do not forward request trailer values to the backend - Redact duplicate TLS certificates in provider merge logs - Fix displayed number on details pages #### v3.7.12 (2026-08-26) - Include the filename in file provider configuration errors - Apply read timeout, idle timeout, and max header bytes for HTTP/3 - Fix redirect www host with a non-numeric port - Fix TLS option name collision across namespaces in the ingress-nginx provider - Reject negative weights in TCP and UDP weighted services #### v3.7.11 (2026-08-19) - Reject out-of-range status codes from backends when using FastProxy - Prevent generated name collisions in the Kubernetes CRD provider - Scope generated Kubernetes Service names to their parent in the CRD provider - Name failover generated services after the referenced Kubernetes Service - Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect - Fix Gateway API router rules - Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider - Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend - Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider - Enforce crossProviderNamespace for Kubernetes Ingress service middleware #### v3.7.10 (2026-07-31) - Fix auth singleflight key collision in middleware authentication (also in v3.6.25) - Avoid router name collisions in Kubernetes Gateway API provider (also in v3.6.25) - Fix cross-namespace service reference check in Kubernetes CRD provider (also in v3.6.25) #### v3.7.9 (2026-07-24) - Fix redirect with use-regex in IngressNGINX provider - Disable Zstd support in the gzhttp wrapper (also in v3.6.24) - Defer the CONNECT payload until the backend accepts the tunnel (also in v3.6.24) - Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy (also in v3.6.24) - Do not add back CONNECT requests to the pool (also in v3.6.24) #### v3.6.24 (2026-07-24) - Add missing ErrorRequestHeaders field to CRDs (also in v3.7.8) - Remove unrelated error from nonexistent cert resolver log (also in v3.7.8) #### v3.7.8 (2026-07-15) - Sanitize rewritten target on ingress-nginx provider - Fix panic in retry middleware with Websockets #### v3.7.7 (2026-07-08) - Add app-root middleware with nginx variable interpolation - Fix consistency between HostSNI(*) and Host(*) - Fix ExtensionRef filters on backendRefs to resolve against the HTTPRoute namespace - Fix handle empty unknown-length bodies in mirroring - Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider (also in v3.6.23) - Sanitize replaced path in ReplacePathRegex middleware (also in v3.6.23) - Fix panic when endpointslice port value or name is nil #### v3.6.23 (2026-07-08) - Fix panic when endpointslice port value or name is nil in Kubernetes provider - Fix handle empty unknown-length bodies in mirroring middleware ### Security #### v3.7.12 (2026-08-26) - Fix CVE GHSA-cjr6-pf59-jq29 - Fix CVE GHSA-7ghq-v6jf-g56c - Fix CVE GHSA-rf44-j88r-hh8c #### v3.7.11 (2026-08-19) - Fix CVE GHSA-5w68-77r2-r64c - Fix CVE GHSA-g55h-rg46-x9c5 - Fix CVE GHSA-j994-9gqj-9hwq - Fix CVE GHSA-m6wx-622r-48r9 #### v3.7.10 (2026-07-31) - Fix CVE GHSA-fgjj-px3w-67xx (also in v3.6.25) - Fix CVE GHSA-62fc-8686-hfmq (also in v3.6.25) - Fix CVE GHSA-6765-c87h-8mrf (also in v3.6.25) #### v3.7.9 (2026-07-24) - Fix advisory GHSA-3ccp-42pg-hgv6 #### v3.6.24 (2026-07-24) - Fix vulnerability GHSA-3ccp-42pg-hgv6 #### v3.7.8 (2026-07-15) - Fix vulnerability GHSA-8rxv-jg7p-wvg3 #### v3.7.7 (2026-07-08) - Fix CVE GHSA-cxjq-mrr5-89rv (also in v3.6.23) - Fix CVE GHSA-42cj-m3vj-89wv (also in v3.6.23) - Fix CVE GHSA-qq9q-x9w4-chhj ## Release notes ### v3.7.13 - Date: 2026-09-04 - Version: v3.7.13 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.13 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.13 - **fixed** — Disable recursive nss propagation by default for DNS challenge - **fixed** — Ignore negated matchers when parsing rule domains - **fixed** — Build a collision-free item key in the Consul Catalog and Nomad providers - **fixed** — Dedicate a transport per HTTP/3 client connection - **fixed** — Fix sticky cookie expiration per request - **fixed** — Create HTTP redirect router for ssl-passthrough with force-ssl-redirect - **fixed** — Preserve leading dot in sticky session cookie Domain attribute - **fixed** — Set access log entry level and time before formatting the OTLP body - **fixed** — Downgrade default TLS resources namespace mismatch log to warning - **fixed** — Fix {url} placeholder in customErrors middleware now includes correct scheme - **fixed** — Prevent user enumeration through the basic auth singleflight key - **fixed** — Build the configuration copy once per change - **fixed** — Do not forward h2c upgrade headers to the backend - **fixed** — Deny request with an opaque request target - **fixed** — Do not forward request trailer values to the backend - **fixed** — Redact duplicate TLS certificates in provider merge logs - **fixed** — Fix displayed number on details pages **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.7/migrate/v3/#v3713). **Bug fixes:** - **[acme]** Bump github.com/go-acme/lego/v5 to v5.4.1 ([#13759](https://github.com/traefik/traefik/pull/13759) @ldez) - **[acme]** Disable recursive nss propagation by default for DNS challenge ([#13830](https://github.com/traefik/traefik/pull/13830) @rtribotte) - **[acme]** Do not require recursive nameservers propagation by default for the DNS-01 challenge ([#13710](https://github.com/traefik/traefik/pull/13710) @amazon7737) - **[acme, tls]** Ignore negated matchers when parsing rule domains ([#13725](https://github.com/traefik/traefik/pull/13725) @rtribotte) - **[consulcatalog, nomad]** Build a collision-free item key in the Consul Catalog and Nomad providers ([#13741](https://github.com/traefik/traefik/pull/13741) @rtribotte) - **[http3]** Dedicate a transport per HTTP/3 client connection ([#13812](https://github.com/traefik/traefik/pull/13812) @sdelicata) - **[k8s/ingress-nginx]** Fix sticky cookie expiration per request ([#13496](https://github.com/traefik/traefik/pull/13496) @makaiver) - **[k8s/ingress-nginx]** Create HTTP redirect router for ssl-passthrough with force-ssl-redirect ([#13457](https://github.com/traefik/traefik/pull/13457) @mmatur) - **[k8s/ingress-nginx]** Preserve leading dot in sticky session cookie Domain attribute ([#13456](https://github.com/traefik/traefik/pull/13456) @mmatur) - **[logs, middleware]** Set access log entry level and time before formatting the OTLP body ([#13767](https://github.com/traefik/traefik/pull/13767) @emilevauge) - **[logs, tls, k8s/crd]** Downgrade default TLS resources namespace mismatch log to warning ([#13780](https://github.com/traefik/traefik/pull/13780) @lazerg) - **[middleware]** Fix {url} placeholder in customErrors middleware now includes correct scheme ([#13320](https://github.com/traefik/traefik/pull/13320) @AnouarMohamed) - **[middleware, authentication]** Prevent user enumeration through the basic auth singleflight key ([#13816](https://github.com/traefik/traefik/pull/13816) @sdelicata) - **[server]** Build the configuration copy once per change ([#13746](https://github.com/traefik/traefik/pull/13746) @jspdown) - **[server]** Do not forward h2c upgrade headers to the backend ([#13797](https://github.com/traefik/traefik/pull/13797) @sdelicata) - **[server]** Deny request with an opaque request target ([#13796](https://github.com/traefik/traefik/pull/13796) @sdelicata) - **[server]** Do not forward request trailer values to the backend ([#13822](https://github.com/traefik/traefik/pull/13822) @rtribotte) - **[server]** Bump github.com/quic-go/quic-go to v0.62.0 ([#13807](https://github.com/traefik/traefik/pull/13807) @Nelwhix) - **[tls]** Redact duplicate TLS certificates in provider merge logs ([#13548](https://github.com/traefik/traefik/pull/13548) @xsergos) - **[webui]** Fix displayed number on details pages ([#13779](https://github.com/traefik/traefik/pull/13779) @gndz07) **Documentation:** - **[k8s]** Add warning about Ingress API frozen state ([#13783](https://github.com/traefik/traefik/pull/13783) @jnoordsij) - **[k8s]** Remove namespace reference for providers.kubernetesGateway.labelSelector ([#13790](https://github.com/traefik/traefik/pull/13790) @jnoordsij) - **[k8s/crd]** Fix broken redirect for the Kubernetes CRD reference docs ([#13811](https://github.com/traefik/traefik/pull/13811) @thev1ndu) - Tell scanning agents to read the security policy and decisions pages ([#13753](https://github.com/traefik/traefik/pull/13753) @emilevauge) ### v3.7.12 - Date: 2026-08-26 - Version: v3.7.12 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.12 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.12 - **security** — Fix CVE GHSA-cjr6-pf59-jq29 - **security** — Fix CVE GHSA-7ghq-v6jf-g56c - **security** — Fix CVE GHSA-rf44-j88r-hh8c - **changed** — Bump github.com/valyala/fasthttp to v1.73.0 - **fixed** — Include the filename in file provider configuration errors - **fixed** — Apply read timeout, idle timeout, and max header bytes for HTTP/3 - **fixed** — Fix redirect www host with a non-numeric port - **fixed** — Fix TLS option name collision across namespaces in the ingress-nginx provider - **added** — Add an entry point option to handle request headers with aliasing names - **fixed** — Reject negative weights in TCP and UDP weighted services - **changed** — Bump etcd client modules to v3.5.33 **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.7/migrate/v3/#v3712). **CVE fixed:** - Advisory [GHSA-cjr6-pf59-jq29](https://github.com/traefik/traefik/security/advisories/GHSA-cjr6-pf59-jq29) - Advisory [GHSA-7ghq-v6jf-g56c](https://github.com/traefik/traefik/security/advisories/GHSA-7ghq-v6jf-g56c) - Advisory [GHSA-rf44-j88r-hh8c](https://github.com/traefik/traefik/security/advisories/GHSA-rf44-j88r-hh8c) **Bug fixes:** - **[fastproxy]** Bump github.com/valyala/fasthttp to v1.73.0 ([#13769](https://github.com/traefik/traefik/pull/13769) @mmatur) - **[file]** Include the filename in file provider configuration errors ([#13527](https://github.com/traefik/traefik/pull/13527) @lazerg) - **[http3]** Apply read timeout, idle timeout, and max header bytes for HTTP/3 ([#13717](https://github.com/traefik/traefik/pull/13717) @gndz07) - **[k8s]** Fix typos in docs and an OCSP log message ([#13722](https://github.com/traefik/traefik/pull/13722) @MsfPablo) - **[k8s, k8s/ingress-nginx]** Fix redirect www host with a non-numeric port ([#13708](https://github.com/traefik/traefik/pull/13708) @mmatur) - **[k8s/ingress-nginx]** Fix TLS option name collision across namespaces in the ingress-nginx provider ([#13721](https://github.com/traefik/traefik/pull/13721) @gndz07) - **[server]** Add an entry point option to handle request headers with aliasing names ([#13720](https://github.com/traefik/traefik/pull/13720) @rtribotte) - **[tcp, udp]** Reject negative weights in TCP and UDP weighted services ([#13749](https://github.com/traefik/traefik/pull/13749) @rtribotte) - Bump etcd client modules to v3.5.33 ([#13756](https://github.com/traefik/traefik/pull/13756) @mmatur) **Documentation:** - **[k8s]** Update redirections block reference in basic.md ([#13723](https://github.com/traefik/traefik/pull/13723) @Larzenegger) - **[k8s]** Fix formatting in Kubernetes setup guide ([#13742](https://github.com/traefik/traefik/pull/13742) @stefkiourk) - **[security]** Document the security threat model and settled security decisions ([#13740](https://github.com/traefik/traefik/pull/13740) @emilevauge) - **[service]** Clarify ServersTransport behavior for the errors middleware in Kubernetes ([#13531](https://github.com/traefik/traefik/pull/13531) @lazerg) - Fix v3.7.11 migration guide ([#13730](https://github.com/traefik/traefik/pull/13730) @gndz07) - Move Jean-Baptiste Doumenjou and Mathieu Lonjaret to past maintainers ([#13736](https://github.com/traefik/traefik/pull/13736) @emilevauge) - Reduce SECURITY.md to a pointer to the security documentation ([#13732](https://github.com/traefik/traefik/pull/13732) @emilevauge) - Update end of support dates ([#13712](https://github.com/traefik/traefik/pull/13712) @nmengin) ### v3.7.11 - Date: 2026-08-19 - Version: v3.7.11 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.11 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.11 - **security** — Fix CVE GHSA-5w68-77r2-r64c - **security** — Fix CVE GHSA-g55h-rg46-x9c5 - **security** — Fix CVE GHSA-j994-9gqj-9hwq - **security** — Fix CVE GHSA-m6wx-622r-48r9 - **fixed** — Reject out-of-range status codes from backends when using FastProxy - **changed** — Bump github.com/quic-go/quic-go to v0.61.0 - **fixed** — Prevent generated name collisions in the Kubernetes CRD provider - **added** — Add an option to restrict the namespace of the default TLS resources - **fixed** — Scope generated Kubernetes Service names to their parent in the CRD provider - **fixed** — Name failover generated services after the referenced Kubernetes Service - **added** — Add safe naming option to avoid collisions for Kubernetes CRD provider - **fixed** — Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect - **fixed** — Fix Gateway API router rules - **fixed** — Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider - **fixed** — Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend - **fixed** — Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider - **fixed** — Enforce crossProviderNamespace for Kubernetes Ingress service middleware - **changed** — Bump github.com/containous/go-http-auth to b975dcaa8c48 - **added** — Add an option to disable the fallback to the default TLS options - **changed** — Bump golang.org/x dependencies **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.7/migrate/v3/#v3711). **CVE fixed:** - Advisory [GHSA-5w68-77r2-r64c](https://github.com/traefik/traefik/security/advisories/GHSA-5w68-77r2-r64c) - Advisory [GHSA-g55h-rg46-x9c5](https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5) - Advisory [GHSA-j994-9gqj-9hwq](https://github.com/traefik/traefik/security/advisories/GHSA-j994-9gqj-9hwq) - Advisory [GHSA-m6wx-622r-48r9](https://github.com/traefik/traefik/security/advisories/GHSA-m6wx-622r-48r9) **Bug fixes:** - **[fastproxy]** Reject out-of-range status codes from backends when using FastProxy ([#13635](https://github.com/traefik/traefik/pull/13635) @gndz07) - **[http3]** Bump github.com/quic-go/quic-go to v0.61.0 ([#13688](https://github.com/traefik/traefik/pull/13688) @jnoordsij) - **[k8s/crd]** Prevent generated name collisions in the Kubernetes CRD provider ([#13656](https://github.com/traefik/traefik/pull/13656) @rtribotte) - **[k8s/crd]** Add an option to restrict the namespace of the default TLS resources ([#13665](https://github.com/traefik/traefik/pull/13665) @rtribotte) - **[k8s/crd]** Scope generated Kubernetes Service names to their parent in the CRD provider ([#13668](https://github.com/traefik/traefik/pull/13668) @rtribotte) - **[k8s/crd]** Name failover generated services after the referenced Kubernetes Service ([#13677](https://github.com/traefik/traefik/pull/13677) @rtribotte) - **[k8s/crd]** Add safe naming option to avoid collisions for Kubernetes CRD provider ([#13689](https://github.com/traefik/traefik/pull/13689) @gndz07) - **[k8s/gatewayapi]** Preserve encoded path segments in Gateway API URLRewrite and RequestRedirect ([#13641](https://github.com/traefik/traefik/pull/13641) @gndz07) - **[k8s/gatewayapi]** Fix Gateway API router rules ([#13645](https://github.com/traefik/traefik/pull/13645) @rtribotte) - **[k8s/ingress-nginx]** Dedupe client-auth TLS options across ingresses sharing a host for ingress-nginx provider ([#13638](https://github.com/traefik/traefik/pull/13638) @gndz07) - **[k8s/ingress-nginx]** Apply auth, custom-headers, custom errors and ssl-redirect to ingress default backend ([#13575](https://github.com/traefik/traefik/pull/13575) @rtribotte) - **[k8s/ingress-nginx]** Honor asDefault and exclude internal entrypoints from default selection for ingress-nginx provider ([#13629](https://github.com/traefik/traefik/pull/13629) @gndz07) - **[k8s/ingress]** Enforce crossProviderNamespace for Kubernetes Ingress service middleware ([#13670](https://github.com/traefik/traefik/pull/13670) @gndz07) - **[middleware, authentication]** Bump github.com/containous/go-http-auth to b975dcaa8c48 ([#13636](https://github.com/traefik/traefik/pull/13636) @kevinpollet) - **[tls]** Add an option to disable the fallback to the default TLS options ([#13639](https://github.com/traefik/traefik/pull/13639) @rtribotte) - Bump golang.org/x dependencies ([#13699](https://github.com/traefik/traefik/pull/13699) @mmatur) **Documentation:** - **[accesslogs]** Clarify OriginStatus and DownstreamStatus in access logs documentation ([#13609](https://github.com/traefik/traefik/pull/13609) @rtribotte) - **[api]** Fix doubled word in API/dashboard reference docs ([#13663](https://github.com/traefik/traefik/pull/13663) @latent-9) - **[docker]** Remove :ro from docker.sock ([#12656](https://github.com/traefik/traefik/pull/12656) @bluepuma77) - **[k8s/gatewayapi]** Clarify v3.7.10 migration guide for Gateway API 1.6.1 ([#13628](https://github.com/traefik/traefik/pull/13628) @rtribotte) - **[k8s/gatewayapi]** Document the Experimental Channel CRDs requirement of the Kubernetes Gateway provider ([#13634](https://github.com/traefik/traefik/pull/13634) @rtribotte) - **[k8s/ingress-nginx]** Docs: Update supported server snippet directives ([#13687](https://github.com/traefik/traefik/pull/13687) @rtsui-harmonicinc) - **[middleware]** Add rejectStatusCode to _[Truncated at 4000 characters — full notes: https://github.com/traefik/traefik/releases/tag/v3.7.11]_ ### v3.7.10 - Date: 2026-07-31 - Version: v3.7.10 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.10 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.10 - **security** — Fix CVE GHSA-fgjj-px3w-67xx - **security** — Fix CVE GHSA-62fc-8686-hfmq - **security** — Fix CVE GHSA-6765-c87h-8mrf - **fixed** — Fix auth singleflight key collision in middleware authentication - **fixed** — Avoid router name collisions in Kubernetes Gateway API provider - **fixed** — Fix cross-namespace service reference check in Kubernetes CRD provider **CVE fixed:** - Advisory [GHSA-fgjj-px3w-67xx](https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx) - Advisory [GHSA-62fc-8686-hfmq](https://github.com/traefik/traefik/security/advisories/GHSA-62fc-8686-hfmq) - Advisory [GHSA-6765-c87h-8mrf](https://github.com/traefik/traefik/security/advisories/GHSA-6765-c87h-8mrf) **Bug fixes:** - **[acme]** Bump github.com/go-acme/lego/v5 to v5.3.1 ([#13547](https://github.com/traefik/traefik/pull/13547) @ldez) - **[middleware, authentication]** Fix auth singleflight key collision ([#13572](https://github.com/traefik/traefik/pull/13572) @mmatur) - **[k8s/gatewayapi]** Avoid router name collisions in Kubernetes Gateway API provider ([#13580](https://github.com/traefik/traefik/pull/13580) @gndz07) - **[tracing]** Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ([#13530](https://github.com/traefik/traefik/pull/13530) @kevinpollet) - Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ([#13574](https://github.com/traefik/traefik/pull/13574) @mmatur) - **[k8s/crd]** Fix cross-namespace service reference check in Kubernetes CRD provider ([#13573](https://github.com/traefik/traefik/pull/13573) @gndz07) - **[middleware]** Bump github.com/klauspost/compress to v1.18.7 ([#13587](https://github.com/traefik/traefik/pull/13587) @mmatur) - **[k8s/gatewayapi]** Bump sigs.k8s.io/gateway-api to v1.6.1 ([#13589](https://github.com/traefik/traefik/pull/13589) @rtribotte) **Documentation:** - **[k8s/ingress-nginx]** Clarify auth-url/rewrite-target interaction on ingress-nginx provider ([#13607](https://github.com/traefik/traefik/pull/13607) @gndz07) ### v3.6.25 - Date: 2026-07-31 - Version: v3.6.25 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.6.25 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.6.25 - **security** — Fix CVE GHSA-fgjj-px3w-67xx - **security** — Fix CVE GHSA-62fc-8686-hfmq - **security** — Fix CVE GHSA-6765-c87h-8mrf - **fixed** — Fix auth singleflight key collision in middleware authentication - **fixed** — Avoid router name collisions in Kubernetes Gateway API provider - **fixed** — Fix cross-namespace service reference check in Kubernetes CRD provider **CVE fixed:** - Advisory [GHSA-fgjj-px3w-67xx](https://github.com/traefik/traefik/security/advisories/GHSA-fgjj-px3w-67xx) - Advisory [GHSA-62fc-8686-hfmq](https://github.com/traefik/traefik/security/advisories/GHSA-62fc-8686-hfmq) - Advisory [GHSA-6765-c87h-8mrf](https://github.com/traefik/traefik/security/advisories/GHSA-6765-c87h-8mrf) **Bug fixes:** - **[acme]** Bump github.com/go-acme/lego/v5 to v5.3.1 ([#13547](https://github.com/traefik/traefik/pull/13547) @ldez) - **[middleware, authentication]** Fix auth singleflight key collision ([#13572](https://github.com/traefik/traefik/pull/13572) @mmatur) - **[k8s/gatewayapi]** Avoid router name collisions in Kubernetes Gateway API provider ([#13580](https://github.com/traefik/traefik/pull/13580) @gndz07) - **[tracing]** Bump github.com/DataDog/dd-trace-go/v2 to 2.8.1 ([#13530](https://github.com/traefik/traefik/pull/13530) @kevinpollet) - Bump golang.org/x/text to v0.40.0 and golang.org/x/net v0.57.0 ([#13574](https://github.com/traefik/traefik/pull/13574) @mmatur) - **[k8s/crd]** Fix cross-namespace service reference check in Kubernetes CRD provider ([#13573](https://github.com/traefik/traefik/pull/13573) @gndz07) - **[middleware]** Bump github.com/klauspost/compress to v1.18.7 ([#13587](https://github.com/traefik/traefik/pull/13587) @mmatur) ### v3.7.9 - Date: 2026-07-24 - Version: v3.7.9 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.9 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.9 - **security** — Fix advisory GHSA-3ccp-42pg-hgv6 - **fixed** — Fix redirect with use-regex in IngressNGINX provider - **fixed** — Disable Zstd support in the gzhttp wrapper - **fixed** — Defer the CONNECT payload until the backend accepts the tunnel - **fixed** — Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy - **changed** — Bump google.golang.org/grpc to v1.82.1 - **fixed** — Do not add back CONNECT requests to the pool **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.7/migrate/v3/#v379). **CVE fixed:** - Advisory [GHSA-3ccp-42pg-hgv6](https://github.com/traefik/traefik/security/advisories/GHSA-3ccp-42pg-hgv6) **Bug fixes:** - **[k8s/ingress-nginx]** Fix redirect with use-regex in IngressNGINX provider ([#13476](https://github.com/traefik/traefik/pull/13476) @AmariahAK) - **[middleware]** Disable Zstd support in the gzhttp wrapper ([#13533](https://github.com/traefik/traefik/pull/13533) @kevinpollet) - **[server]** Defer the CONNECT payload until the backend accepts the tunnel ([#13542](https://github.com/traefik/traefik/pull/13542) @sdelicata) - **[server]** Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy ([#13543](https://github.com/traefik/traefik/pull/13543) @sdelicata) - **[server]** Bump google.golang.org/grpc to v1.82.1 ([#13551](https://github.com/traefik/traefik/pull/13551) @piscue) - **[server]** Do not add back CONNECT requests to the pool ([#13556](https://github.com/traefik/traefik/pull/13556) @kevinpollet) **Documentation:** - **[k8s/gatewayapi]** Document Gateway API generated service names change in the migration guide ([#13541](https://github.com/traefik/traefik/pull/13541) @rtribotte) - **[k8s/ingress-nginx]** Fix typo in nginx annotation proxy-buffer-numbers ([#13545](https://github.com/traefik/traefik/pull/13545) @fischerman) - Add a migration note for CONNECT requests ([#13554](https://github.com/traefik/traefik/pull/13554) @kevinpollet) ### v3.6.24 - Date: 2026-07-24 - Version: v3.6.24 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.6.24 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.6.24 - **security** — Fix vulnerability GHSA-3ccp-42pg-hgv6 - **fixed** — Add missing ErrorRequestHeaders field to CRDs - **fixed** — Remove unrelated error from nonexistent cert resolver log - **fixed** — Disable Zstd support in the gzhttp wrapper - **fixed** — Defer the CONNECT payload until the backend accepts the tunnel - **fixed** — Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy - **changed** — Bump google.golang.org/grpc to v1.82.1 - **fixed** — Do not add back CONNECT requests to the pool **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.6/migrate/v3/#v3624). **CVE fixed:** - Advisory [GHSA-3ccp-42pg-hgv6](https://github.com/traefik/traefik/security/advisories/GHSA-3ccp-42pg-hgv6) **Bug fixes:** - **[middleware, k8s/crd]** Add missing ErrorRequestHeaders field to CRDs ([#13498](https://github.com/traefik/traefik/pull/13498) @kevinpollet) - **[logs]** Remove unrelated error from nonexistent cert resolver log ([#13469](https://github.com/traefik/traefik/pull/13469) @ArthurHlt) - **[middleware]** Disable Zstd support in the gzhttp wrapper ([#13533](https://github.com/traefik/traefik/pull/13533) @kevinpollet) - **[server]** Defer the CONNECT payload until the backend accepts the tunnel ([#13542](https://github.com/traefik/traefik/pull/13542) @sdelicata) - **[server]** Discard CONNECT body in forwardauth and reject CONNECT requests with fast proxy ([#13543](https://github.com/traefik/traefik/pull/13543) @sdelicata) - **[server]** Bump google.golang.org/grpc to v1.82.1 ([#13551](https://github.com/traefik/traefik/pull/13551) @piscue) - **[server]** Do not add back CONNECT requests to the pool ([#13556](https://github.com/traefik/traefik/pull/13556) @kevinpollet) **Documentation:** - **[k8s]** Align certificateRef and indicate ports ([#13473](https://github.com/traefik/traefik/pull/13473) @veenoise) - **[rules]** Fix syntax notes in routing rule documentation ([#13501](https://github.com/traefik/traefik/pull/13501) @stevenlele) - Add a migration note for CONNECT requests ([#13554](https://github.com/traefik/traefik/pull/13554) @kevinpollet) ### v3.7.8 - Date: 2026-07-15 - Version: v3.7.8 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.8 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.8 - **security** — Fix vulnerability GHSA-8rxv-jg7p-wvg3 - **fixed** — Add missing ErrorRequestHeaders field to CRDs - **fixed** — Sanitize rewritten target on ingress-nginx provider - **fixed** — Remove unrelated error from nonexistent cert resolver log - **fixed** — Fix panic in retry middleware with Websockets **CVE fixed:** - Advisory [GHSA-8rxv-jg7p-wvg3](https://github.com/traefik/traefik/security/advisories/GHSA-8rxv-jg7p-wvg3) **Bug fixes:** - **[middleware, k8s/crd]** Add missing ErrorRequestHeaders field to CRDs ([#13498](https://github.com/traefik/traefik/pull/13498) @kevinpollet) - **[k8s/ingress-nginx]** Sanitize rewritten target on ingress-nginx provider ([#13506](https://github.com/traefik/traefik/pull/13506) @gndz07) - **[logs]** Remove unrelated error from nonexistent cert resolver log ([#13469](https://github.com/traefik/traefik/pull/13469) @ArthurHlt) - **[middleware]** Fix panic in retry middleware with Websockets ([#13520](https://github.com/traefik/traefik/pull/13520) @juliens) **Documentation:** - **[k8s]** Align certificateRef and indicate ports ([#13473](https://github.com/traefik/traefik/pull/13473) @veenoise) - **[rules]** Fix syntax notes in routing rule documentation ([#13501](https://github.com/traefik/traefik/pull/13501) @stevenlele) - **[k8s/crd]** Fix duplicated options table in ServersTransport CRD reference ([#13518](https://github.com/traefik/traefik/pull/13518) @rachana5) ### v3.7.7 - Date: 2026-07-08 - Version: v3.7.7 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.7.7 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.7.7 - **security** — Fix CVE GHSA-cxjq-mrr5-89rv - **security** — Fix CVE GHSA-42cj-m3vj-89wv - **security** — Fix CVE GHSA-qq9q-x9w4-chhj - **fixed** — Add app-root middleware with nginx variable interpolation - **fixed** — Fix consistency between HostSNI(*) and Host(*) - **fixed** — Fix ExtensionRef filters on backendRefs to resolve against the HTTPRoute namespace - **fixed** — Fix handle empty unknown-length bodies in mirroring - **fixed** — Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider - **fixed** — Sanitize replaced path in ReplacePathRegex middleware - **changed** — Bump software.sslmate.com/src/go-pkcs12 to v0.7.3 - **changed** — Bump go.opentelemetry.io/otel to v1.44.0 - **fixed** — Fix panic when endpointslice port value or name is nil **Important:** Please read the [migration guide](https://doc.traefik.io/traefik/v3.7/migrate/v3/#v377). **CVE fixed:** - Advisory [GHSA-cxjq-mrr5-89rv](https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv) - Advisory [GHSA-42cj-m3vj-89wv](https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv) - Advisory [GHSA-qq9q-x9w4-chhj](https://github.com/traefik/traefik/security/advisories/GHSA-qq9q-x9w4-chhj) **Bug fixes:** - **[middleware, k8s/ingress-nginx]** Add app-root middleware with nginx variable interpolation ([#13398](https://github.com/traefik/traefik/pull/13398) @dfeinblatt) - **[rules]** Fix consistency between HostSNI(*) and Host(*) ([#13460](https://github.com/traefik/traefik/pull/13460) @juliens) - **[k8s, k8s/gatewayapi]** Fix ExtensionRef filters on backendRefs to resolve against the HTTPRoute namespace ([#13462](https://github.com/traefik/traefik/pull/13462) @gndz07) - **[middleware]** Fix handle empty unknown-length bodies in mirroring ([#13399](https://github.com/traefik/traefik/pull/13399) @amazon7737) - **[k8s/crd]** Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider ([#13458](https://github.com/traefik/traefik/pull/13458) @gndz07) - **[middleware]** Sanitize replaced path in ReplacePathRegex middleware ([#13466](https://github.com/traefik/traefik/pull/13466) @kevinpollet) - **[acme]** Bump software.sslmate.com/src/go-pkcs12 to v0.7.3 ([#13477](https://github.com/traefik/traefik/pull/13477) @rtribotte) - **[otel]** Bump go.opentelemetry.io/otel to v1.44.0 ([#13478](https://github.com/traefik/traefik/pull/13478) @rtribotte) - **[k8s]** Fix panic when endpointslice port value or name is nil ([#13481](https://github.com/traefik/traefik/pull/13481) @kevinpollet) **Documentation:** - Fix version in migration guide ([#13434](https://github.com/traefik/traefik/pull/13434) @kevinpollet) - Fix changelog v2.11.51 ([#13430](https://github.com/traefik/traefik/pull/13430) @mmatur) - Add v3.7 to supported version docs ([#13118](https://github.com/traefik/traefik/pull/13118) @jnoordsij) - Fix some function names in comments ([#13443](https://github.com/traefik/traefik/pull/13443) @blackflytech) - Add @nandorKollar as a current maintainer ([#13451](https://github.com/traefik/traefik/pull/13451) @emilevauge) - Add @amazon7737 as a current maintainer ([#13450](https://github.com/traefik/traefik/pull/13450) @emilevauge) - **[middleware]** Clarify buffering middleware defaults ([#13401](https://github.com/traefik/traefik/pull/13401) @amazon7737) - Fix grammar in TLS, TCP service, and routing reference docs ([#13461](https://github.com/traefik/traefik/pull/13461) @almightymoon) - Fix X-Forwarded-Prefix documentation for dashboard redirection ([#13472](https://github.com/traefik/traefik/pull/13472) @kevinpollet) ### v3.6.23 - Date: 2026-07-08 - Version: v3.6.23 - Original notes: https://github.com/traefik/traefik/releases/tag/v3.6.23 - Permalink: https://whatsnew.fyi/product/traefik/releases/v3.6.23 - **security** — Fix CVE GHSA-cxjq-mrr5-89rv - **security** — Fix CVE GHSA-42cj-m3vj-89wv - **fixed** — Fix panic when endpointslice port value or name is nil in Kubernetes provider - **fixed** — Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider - **fixed** — Fix handle empty unknown-length bodies in mirroring middleware - **fixed** — Sanitize replaced path in ReplacePathRegex middleware **CVE fixed:** - Advisory [GHSA-cxjq-mrr5-89rv](https://github.com/traefik/traefik/security/advisories/GHSA-cxjq-mrr5-89rv) - Advisory [GHSA-42cj-m3vj-89wv](https://github.com/traefik/traefik/security/advisories/GHSA-42cj-m3vj-89wv) **Bug fixes:** - **[acme]** Bump software.sslmate.com/src/go-pkcs12 to v0.7.3 ([#13477](https://github.com/traefik/traefik/pull/13477) @rtribotte) - **[k8s]** Fix panic when endpointslice port value or name is nil ([#13481](https://github.com/traefik/traefik/pull/13481) @kevinpollet) - **[k8s/crd]** Fix cross-provider ref check for TCP ServersTransport in Kubernetes CRD provider ([#13458](https://github.com/traefik/traefik/pull/13458) @gndz07) - **[middleware]** Fix handle empty unknown-length bodies in mirroring ([#13399](https://github.com/traefik/traefik/pull/13399) @amazon7737) - **[middleware]** Sanitize replaced path in ReplacePathRegex middleware ([#13466](https://github.com/traefik/traefik/pull/13466) @kevinpollet) - **[otel]** Bump go.opentelemetry.io/otel to v1.44.0 ([#13478](https://github.com/traefik/traefik/pull/13478) @rtribotte) **Documentation:** - **[middleware]** Clarify buffering middleware defaults ([#13401](https://github.com/traefik/traefik/pull/13401) @amazon7737) - Add @amazon7737 as a current maintainer ([#13450](https://github.com/traefik/traefik/pull/13450) @emilevauge) - Add @nandorKollar as a current maintainer ([#13451](https://github.com/traefik/traefik/pull/13451) @emilevauge) - Fix changelog v2.11.51 ([#13430](https://github.com/traefik/traefik/pull/13430) @mmatur) - Fix grammar in TLS, TCP service, and routing reference docs ([#13461](https://github.com/traefik/traefik/pull/13461) @almightymoon) - Fix some function names in comments ([#13443](https://github.com/traefik/traefik/pull/13443) @blackflytech) - Fix version in migration guide ([#13434](https://github.com/traefik/traefik/pull/13434) @kevinpollet) - Fix X-Forwarded-Prefix documentation for dashboard redirection ([#13472](https://github.com/traefik/traefik/pull/13472) @kevinpollet)