CVE-2026-39858

HIGH EPSS 39.9%
Published Apr 30, 20262mo ago · Modified Jun 17, 20261w ago
7.8 CVSS 4.0
High
Find Similar
Published Apr 30, 2026 2mo ago
Last Modified Jun 17, 2026 1w ago

Description

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canonical header names (e.g., X-Forwarded-Proto) and does not strip or normalize alias variants that use underscores instead of dashes (e.g., X_Forwarded_Proto). These unsanitized alias headers are forwarded intact to the authentication backend. When the backend normalizes underscore and dash header forms equivalently, an attacker can inject spoofed trust context — such as a trusted scheme or host — through the alias headers and bypass authentication on protected routes without valid credentials. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

CVSS Details

Base Score
7.8
Exploitability
Impact
Vector string
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope X

Threat Intelligence

EPSS Exploit Probability
39.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available

Weaknesses 2

CWE-290
CWE-306 Missing Authentication for Critical Function Authentication

Affected Products 6

VendorProductVersionRange
traefiktraefik* <2.11.43
traefiktraefik*≥3.0.0  –  <3.6.14
traefiktraefik3.7.0any
traefiktraefik3.7.0any
traefiktraefik3.7.0any
traefiktraefik3.7.0any

References 4

  • github.com https://github.com/traefik/traefik/releases/tag/v2.11.43
    ProductRelease Notes
  • github.com https://github.com/traefik/traefik/releases/tag/v3.6.14
    ProductRelease Notes
  • github.com https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2
    ProductRelease Notes
  • github.com https://github.com/traefik/traefik/security/advisories/GHSA-5m6w-wvh7-57vm
    ExploitMitigationPatchVendor Advisory

Remediation

  • github.com https://github.com/traefik/traefik/security/advisories/GHSA-5m6w-wvh7-57vm
    ExploitMitigationPatchVendor Advisory