CVE-2026-39858Disclosure(traefik / traefik)

LOWCVSS 10.0 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippet-based authentication middleware. Traefik's forwarded-header sanitization logic targets only canonical header names (e.g., X-Forwarded-Proto) and does not strip or normalize alias variants that use underscores instead of dashes (e.g., X_Forwarded_Proto). These unsanitized alias headers are forwarded intact to the authentication backend. When the backend normalizes underscore and dash header forms equivalently, an attacker can inject spoofed trust context — such as a trusted scheme or host — through the alias headers and bypass authentication on protected routes without valid credentials. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-290CWE-306CWE-289

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 2 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-12)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
traefik

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-04-30: 1Mentions · 2026-05-01: 1Mentions · 2026-05-12: 5Patch / Workaround · 2026-04-30: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-01: 1Technical Details · 2026-05-12: 404-3005-0105-12
Signal classification3 categories
Disclosure
457.1%
General
228.6%
Patch
114.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-301
Patch1
2026-05-011
Disclosure1
2026-05-125
Disclosure3General2
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-39858 (CVSS 10) — traefik traefik. CVE: CVE-2026-39858 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The content announces CVE‑2026‑39858 as a critical vulnerability with a CVSS score of 10, but provides no PoC, exploit, patch, or evidence of active exploitation.

    1000031
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-39858 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The advisory announces CVE-2026-39858 as a critical vulnerability with a maximum CVSS score of 10, highlighting its severity but providing no proof of exploitation or mitigation info.

    1000033
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-39858 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory Traefik is an HTTP reverse proxy and load balancer.

    Post summary

    The text reports the discovery of CVE-2026-39858 as a critical vulnerability in Traefik, noting its high CVSS score and advisory status, but provides no further details on exploitation or remediation.

    1000035
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    References CVE: CVE-2026-39858 CVSS: 10 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces a new critical vulnerability (CVE-2026-39858) with detailed CVSS metrics, but provides no evidence of PoC, exploit code, active exploitation, or mitigation steps.

    1000026
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-39858-traefik-traefik #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The tweet solely links to a research page about CVE-2026-39858 and offers no further detail.

    0000026
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39858 Authentication Bypass in Traefik ForwardAuth via Unsanitized Header Aliases https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39858

    Post summary

    The text announces a new authentication bypass vulnerability in Traefik ForwardAuth linked to unsanitized header aliases, but no PoC, exploit code, patch, or active exploitation claims are provided.

    0000044
    4.0K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-39858 Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in… https://www.cve.org/CVERecord?id=CVE-2026-39858

    Post summary

    CVE-2026-39858 is an authentication bypass flaw affecting older Traefik versions; newer releases up to 2.11.43, 3.6.14, and 3.7.0‑rc.2 contain the fix.

    00000129
    57.4K followersView on X
CPE platform detail5 entries

5 of 5 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--
Apptraefiktraefik3.7.0--

Explore more