PT-2026-76028 · Go · Github.Com/Traefik/Traefik+2
Published
2026-08-11
·
Updated
2026-08-11
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Traefik's errors middleware by default forwards all original request headers to the error page service. If the error page service is in a separate trust domain, this can lead to the disclosure of sensitive information such as Authorization or Cookie headers.
The fix adds an errorRequestHeaders option to the Errors middleware, allowing users to explicitly list which headers should be forwarded.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Github.Com/Traefik/Traefik
Github.Com/Traefik/Traefik/V2
Github.Com/Traefik/Traefik/V3