Feed/CVE-2026-54764
CVE-2026-54764MEDIUMCVSS 5.8

CVE-2026-54764

Published Jul 6, 2026·Updated Aug 6, 2026

NVD Description

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.

Affected Packages (3)

github.com/traefik/traefikGO
Fixed in = 1.7.34
github.com/traefik/traefik/v2GO
Fixed in = 2.11.50
github.com/traefik/traefik/v3GO
Fixed in = 3.6.21

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free