CVE-2026-29054Disclosure(traefik / traefik)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik managing the Connection header with X-Forwarded headers. When Traefik processes HTTP/1.1 requests, the protection put in place to prevent the removal of Traefik-managed X-Forwarded headers (such as X-Real-Ip, X-Forwarded-Host, X-Forwarded-Port, etc.) via the Connection header does not handle case sensitivity correctly. The Connection tokens are compared case-sensitively against the protected header names, but the actual header deletion operates case-insensitively. As a result, a remote unauthenticated client can use lowercase Connection tokens (e.g. Connection: x-real-ip) to bypass the protection and trigger the removal of Traefik-managed forwarded identity headers. This issue has been patched in versions 2.11.38 and 3.6.9.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-03-05); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-03-05: 1Mentions · 2026-03-06: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-03-06: 1Technical Details · 2026-04-13: 103-0503-0604-13
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-051
Disclosure1
2026-03-061
General1
2026-04-131
Disclosure1
Full discourse3 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-29054 Traefik Header Manipulation Vulnerability Allows Unauthorized Header Removal https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-29054

    Post summary

    The text announces the existence of CVE-2026-29054, a header manipulation flaw in Traefik that allows unauthorized removal of HTTP headers, but provides no evidence of PoC, exploitation, or remediation.

    0001043
    4.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Traefik` is affected by CVE-2026-29054, a header deletion bypass via lowercase `Connection` tokens, impacting forwarded identity headers like `X-Real-Ip`. Monitor for patches. #Traefik #CVE #infosec https://www.pulsepatch.io/posts/cve-2026-29054-traefik-header-bypass

    Post summary

    Traefik suffers a header deletion bypass (CVE‑2026‑29054) that can strip identity headers via lowercase `Connection` tokens; no PoC or exploit code is disclosed, and no active exploitation is reported, but users should monitor for vendor patches.

    0000031
    13 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-29054 Traefik is an HTTP reverse proxy and load balancer. From version 2.11.9 to 2.11.37 and from version 3.1.3 to 3.6.8, there is a potential vulnerability in Traefik mana… https://www.cve.org/CVERecord?id=CVE-2026-29054

    Post summary

    The text announces a potential vulnerability in Traefik across specific version ranges, linking to the CVE record, without providing exploit, patch, or technical detail.

    00000118
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more