CVE-2026-33433Patch(traefik / traefik)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The backend receives two header entries — the attacker-injected canonical one is read first, overriding Traefik's non-canonical write. Versions 2.11.42, 3.6.11, and 3.7.0-ea.3 patch the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
traefik

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-07: 1Patch / Workaround · 2026-08-07: 1Technical Details · 2026-08-07: 108-07
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨High - Traefik BasicAuth/DigestAuth Identity Spoof via headerField Canonicalization (CVE-2026-33433) Traefik BasicAuth/DigestAuth can be bypassed when headerField is set to a non-canonical HTTP header name: an authenticated attacker injects the canonical header variant and the backend reads it first, overriding Traefik’s non-canonical write to impersonate another identity. Default/canonical headerField configs aren’t affected. 👉Affected: Traefik < 2.11.42, 3.6.x < 3.6.11, 3.7.0-ea < 3.7.0-ea.3 | Upgrade to 2.11.42 / 3.6.11 / 3.7.0-ea.3

    Post summary

    CVE‑2026‑33433 enables identity spoofing in Traefik BasicAuth/DigestAuth via non‑canonical headerField; upgrading to the listed patch versions mitigates the issue.

    0000072
    282 followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--

Explore more