cbcvebase.
CVE-2026-54763
published 2026-07-06

CVE-2026-54763: Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip…

PriorityP259critical10CVSS 3.1
AVNACLPRNUINSCCHIHAN
EPSS
0.21%
10.9th percentile
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.

Affected

9 ranges
VendorProductVersion rangeFixed in
devspacestraefik-rhel9
github.comtraefik_traefik_v2>= 0 < 2.11.512.11.51
github.comtraefik_traefik_v3>= 0 < 3.6.223.6.22
github.comtraefik_traefik_v3>= 3.7.0 < 3.7.63.7.6
traefiktraefik< 2.11.512.11.51
traefiktraefik
traefiktraefik
traefiktraefik>= 3.0.0 < 3.6.223.6.22
traefiktraefik>= 3.7.0 < 3.7.63.7.6

CVSS provenance

nvdv3.110.0CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
nvdv4.07.8HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
ghsa8.8HIGH
vendor_redhat10.0CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.