CVE-2025-54386 | Traefik up to 2.11.27/3.4.4/3.5.0-rc1 ZIP Archive path traversal (GHSA-q6gg-9f92-r9wg / EUVD-2025-23415)
A vulnerability categorized as critical has been discovered in Traefik up to 2.11.27/3.4.4/3.5.0-rc1. The impacted element is an unknown function of the component ZIP Archive Handler. Such manipulation leads to path traversal.
This vulnerability is listed as CVE-2025-54386. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.