Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-33433

Опубликовано: 27 мар. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when headerField is configured with a non-canonical HTTP header name (e.g., x-auth-user instead of X-Auth-User), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The backend receives two header entries — the attacker-injected canonical one is read first, overriding Traefik's non-canonical write. Versions 2.11.42, 3.6.11, and 3.7.0-ea.3 patch the issue.

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. When the headerField is configured with a non-canonical HTTP header name, an authenticated attacker can inject a canonical version of that header. This allows the attacker to impersonate any identity to the backend, leading to an authentication bypass. The backend prioritizes the attacker-injected header, overriding Traefik's intended header.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Дополнительная информация

Статус:

Important
Дефект:
CWE-290
https://bugzilla.redhat.com/show_bug.cgi?id=2452289github.com/traefik/traefik: Traefik: Authentication bypass via non-canonical HTTP header injection

EPSS

Процентиль: 38%
0.00469
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The backend receives two header entries — the attacker-injected canonical one is read first, overriding Traefik's non-canonical write. Versions 2.11.42, 3.6.11, and 3.7.0-ea.3 patch the issue.

CVSS3: 8.8
debian
5 месяцев назад

Traefik is an HTTP reverse proxy and load balancer. Prior to versions ...

github
5 месяцев назад

Traefik Vulnerable to BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField

CVSS3: 8.8
fstec
больше 1 года назад

Уязвимость обратного прокси сервера Containous Traefik, связанная с обходом аутентификации посредством спуфинга, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 38%
0.00469
Низкий

7.7 High

CVSS3