PT-2026-55998 · Traefik · Traefik
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions prior to 2.11.51
Traefik versions prior to 3.6.22
Traefik versions prior to 3.7.6
Description
The ForwardAuth middleware in this HTTP reverse proxy and load balancer incorrectly derives the
X-Forwarded-Port header sent to the authentication service from the original incoming request rather than the sanitized forwarded request, even when trustForwardHeader is set to false. This allows an unauthenticated remote attacker to inject an X-Forwarded-Proto: https header via a plain HTTP connection, leading the system to forward X-Forwarded-Port: 443 to the authentication service and bypass port-based authorization checks.Recommendations
Update to version 2.11.51.
Update to version 3.6.22.
Update to version 3.7.6.
Exploit
Fix
Insufficient Verification of Data Authenticity
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Traefik