CVE-2026-54764Disclosure(traefik / traefik)

LOWCVSS 5.8 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-07-08: 1Technical Details · 2026-07-08: 107-08
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
Full discourse1 post
  • ThreatAft@ThreatAft
    Disclosure

    🚨 CRITICAL: Traefik 3-CVE Cluster — CVSS 10.0 CVE-2026-54763: Header injection bypasses BasicAuth/DigestAuth/ForwardAuth. CVE-2026-54764: ForwardAuth port bypass (8.5) CVE-2026-54765: K8s Gateway context leak (5.8) 🔗 https://threataft.com/articles/traefik-cve-2026-54763-54764-54765-auth-bypass?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #Traefik #infosec

    Post summary

    The tweet announces three critical Traefik CVEs, detailing authentication bypasses and a Kubernetes context leak with CVSS scores, but provides no PoC, exploit code, active attack information, or patch details.

    0000060
    34 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more