Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-35051

Опубликовано: 30 апр. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

A flaw was found in Traefik, an HTTP reverse proxy and load balancer. This authentication bypass vulnerability exists in Traefik's ForwardAuth middleware when the trustForwardHeader setting is configured as false and Traefik is deployed behind a trusted upstream proxy. A remote attacker could exploit this to bypass authentication, potentially gaining unauthorized access to protected resources.

Меры по смягчению последствий

To mitigate this issue, ensure that the trustForwardHeader setting in Traefik's ForwardAuth middleware is not explicitly configured as false unless absolutely necessary. If Traefik is deployed behind a trusted upstream proxy, review the configuration to ensure that trustForwardHeader is either set to true or omitted, allowing Traefik to correctly process forwarded headers for authentication. If this configuration is modified, a restart or reload of the Traefik service may be required for the changes to take effect.

Дополнительная информация

Статус:

Important
Дефект:
CWE-501
https://bugzilla.redhat.com/show_bug.cgi?id=2464235Traefik: github.com/traefik/traefik: Traefik: Authentication bypass in ForwardAuth middleware

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 10
nvd
3 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

CVSS3: 10
debian
3 месяца назад

Traefik is an HTTP reverse proxy and load balancer. Prior to versions ...

CVSS3: 10
github
4 месяца назад

Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication

CVSS3: 10
fstec
4 месяца назад

Уязвимость промежуточного программного обеспечения ForwardAuth обратного прокси сервера Containous Traefik, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 19%
0.00267
Низкий

8.2 High

CVSS3