Executive brief
Traefik, a popular tool used to route and manage web traffic, contains a flaw in how it handles security headers that identify the origin of a request. An attacker can trick the system into stripping away these identity headers, such as the user's real IP address. This can allow unauthorized users to bypass security rules or access controls that rely on knowing where a request actually came from.
Technical details
A vulnerability exists in Traefik's XForwarded middleware (specifically the removeConnectionHeaders function) due to improper handling of case sensitivity. While Traefik attempts to protect internal headers like X-Real-Ip and X-Forwarded-* from being manipulated via the HTTP/1.1 Connection header, it performs a case-sensitive membership check against a list of protected headers while the subsequent deletion is case-insensitive. A remote unauthenticated attacker can send a request with lowercase tokens in the Connection header (e.g., 'Connection: x-real-ip') to bypass the protection and force Traefik to strip its own managed identity headers. This can lead to an authentication or authorization bypass if downstream services rely on these headers for IP allowlisting or trust decisions. The issue is a bypass of the fix for CVE-2024-45410 and has been patched in versions 2.11.38 and 3.6.9.
Affected products
- Traefik Proxy Traefik >= 2.11.9, < 2.11.38; >= 3.1.3, < 3.6.9
- Red Hat Red Hat OpenShift Dev Spaces 3.27 3.27.1
Timeline
- 2026-03-04: advisory: GitHub Security Advisory GHSA-92mv-8f8w-wq52 published
- 2026-03-05: disclosed: CVE-2026-29054 published to NVD
- 2026-04-23: patched: Red Hat released security advisory RHSA-2026:10175
References
- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9
- https://github.com/traefik/traefik/security/advisories/GHSA-92mv-8f8w-wq52
- https://access.redhat.com/errata/RHSA-2026:10175
- https://access.redhat.com/security/cve/CVE-2026-29054
- https://bugzilla.redhat.com/show_bug.cgi?id=2444872
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-29054.json