10

CVE-2026-35051

Exploit

Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Traefik ≫ Traefik Version < 2.11.43
Traefik ≫ Traefik Version >= 3.0.0 < 3.6.14
Traefik ≫ Traefik Version 3.7.0 Update ea1
Traefik ≫ Traefik Version 3.7.0 Update ea2
Traefik ≫ Traefik Version 3.7.0 Update ea3
Traefik ≫ Traefik Version 3.7.0 Update rc1
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.27% 0.183
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 5.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
security-advisories@github.com 7.8 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
0b0ca135-0b70-47e7-9f44-1890c2a1c46c 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CWE-345 Insufficient Verification of Data Authenticity

The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

CWE-501 Trust Boundary Violation

The product mixes trusted and untrusted data in the same data structure or structured message.

https://github.com/traefik/traefik/releases/tag/v2.11.43
Product
Release Notes
https://github.com/traefik/traefik/releases/tag/v3.6.14
Product
Release Notes
https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2
Product
Release Notes
https://bugzilla.redhat.com/show_bug.cgi?id=2464235
https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35051.json
https://access.redhat.com/errata/RHSA-2026:21772
https://github.com/traefik/traefik/security/advisories/GHSA-6384-m2mw-rf54
Patch
Vendor Advisory
Exploit
https://access.redhat.com/security/cve/CVE-2026-35051