CVE-2026-54763Disclosure(traefik / traefik)

LOWCVSS 10.0 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-178CWE-290CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-07-08); latest day: 1
  • 5 total mentions across 5 days

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-07-08: 1Mentions · 2026-07-10: 1Mentions · 2026-08-03: 1Mentions · 2026-08-13: 1Mentions · 2026-09-11: 1Patch / Workaround · 2026-07-10: 1Patch / Workaround · 2026-08-03: 1Technical Details · 2026-07-08: 1Technical Details · 2026-07-10: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-13: 1Technical Details · 2026-09-11: 107-0807-1008-0308-1309-11
Signal classification3 categories
Disclosure
240.0%
Patch
240.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-07-081
Disclosure1
2026-07-101
Patch1
2026-08-031
Patch1
2026-08-131
General1
2026-09-111
Disclosure1
Full discourse5 posts
  • Autumn Good@autumn_good_35
    General

    Severity: CRITICAL Traefik Authentication Middleware Header Handling Vulnerability (CVE-2026-54763) Grafana Dashboard Privilege Escalation Vulnerability (CVE-2026-33377) Multiple Vulnerabilities in HPE Aruba Networking Private 5G Core https://csaf.arubanetworking.hpe.com/2026/hpe_aruba_networking_-_hpesbnw05119.txt

    Post summary

    The excerpt lists several critical CVEs for Traefik, Grafana and HPE Aruba 5G core, offering minimal technical details and a CSAF link, but no PoC, exploit, active usage, or patch information.

    00011629
    7.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 HIGH - Traefik auth middleware header normalization bypass (CVE-2026-54763) Traefik’s BasicAuth, DigestAuth, and ForwardAuth middlewares improperly sanitize identity-related headers, stripping canonical-cased spoofed headers but missing underscore-variant header names that some backends normalize into dashed equivalents. The root cause is improper input validation / header normalization mismatch, where Traefik’s filtering logic doesn’t account for alternate header spellings that downstream servers treat as the same header. An attacker with network access to a protected route can send underscore-variant headers (or override ForwardAuth authResponseHeaders) that Traefik fails to remove, allowing them to reach and influence backend request context. Impact includes identity spoofing and authorization bypass at the backend, potentially leading to unauthorized access and data exposure depending on what headers the application trusts. 👉 Affected: traefik <2.11.51, 3.6.x <3.6.22, 3.7.x <3.7.6 | Upgrade to 2.11.51 / 3.6.22 / 3.7.6

    Post summary

    The CVE details a header normalization bypass in Traefik’s authentication middlewares that enables identity spoofing; upgrading to the mentioned versions mitigates the issue.

    0001099
    246 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 Traefik, HTTP Trailer Sanitization Bypass, #CVE-2026-54763 (critical) -DC-Sep2026-2352 https://dailycve.com/traefik-http-trailer-sanitization-bypass-cve-2026-54763-critical-dc-sep2026-2352/

    Post summary

    A critical CVE‑2026‑54763 concerning an HTTP Trailer Sanitization Bypass in Traefik has been publicly disclosed, with no indication of active exploitation, PoC, or patch yet.

    0000038
    237 followersView on X
  • takenaka hiroya@Joe_Biden_ja
    Patch

    Traefik の認証ミドルウェアが、ハイフン版のIDヘッダだけを剥がしてアンダースコア版を見逃していました。後段のPHPやNginxはこの2つを同じに正規化するので、誰として通ったかが書き換わります。CVSS 10.0。修正は v2.11.51 / v3.6.22 / v3.… https://cve.autoarticles.net/cve/CVE-2026-54763

    Post summary

    Traefik’s authentication middleware fails to normalize ID headers, enabling user impersonation (CVSS 10.0). Patches v2.11.51 and v3.6.22 are already released.

    0000071
    561 followersView on X
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: Traefik 3-CVE Cluster — CVSS 10.0 CVE-2026-54763: Header injection bypasses BasicAuth/DigestAuth/ForwardAuth. CVE-2026-54764: ForwardAuth port bypass (8.5) CVE-2026-54765: K8s Gateway context leak (5.8) 🔗 https://threataft.com/articles/traefik-cve-2026-54763-54764-54765-auth-bypass?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Traefik #infosec

    Post summary

    The tweet announces three critical Traefik CVEs, offering brief technical details but no proof of exploitation, patches, or active attacks.

    0000060
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more