Junglewise Threat Intelligence

CVE-2026-35051: Traefik auth bypass in ForwardAuth middleware via header spoofing

CVE-2026-35051 · Severity: critical · CVSS 10 · Published 2026-04-30

Technologies: Traefik Labs Traefik Proxy, github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Traefik Labs, Red Hat, Go.

Executive brief

Traefik, a popular tool used to manage and route web traffic, contains a security flaw that could allow unauthorized users to bypass login requirements. When Traefik is set up behind another proxy server, an attacker can send specially crafted web requests that trick the system into granting access to protected areas. This could lead to the exposure of sensitive customer data or unauthorized control over internal business applications.

Technical details

An authentication bypass vulnerability exists in Traefik's ForwardAuth middleware due to insufficient verification of data authenticity. When Traefik is configured with 'trustForwardHeader=false' and deployed behind a trusted upstream proxy, the middleware fails to strip or rebuild the 'X-Forwarded-Prefix' header before sending subrequests to the authentication service. While other 'X-Forwarded-*' headers are correctly handled, the 'X-Forwarded-Prefix' remains attacker-controlled. If the downstream authentication service relies on this header to make authorization or routing decisions, a remote, unauthenticated attacker can spoof the prefix to bypass access controls. The issue is patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

Affected products

  • Traefik Labs Traefik < 2.11.43, >= 3.0.0-beta1 < 3.6.14, >= 3.7.0-ea.1 < 3.7.0-rc.2
  • Red Hat Red Hat OpenShift Dev Spaces 3.28 3.28

Timeline

  • 2026-04-22: patched: Fixed versions 2.11.43, 3.6.14, and 3.7.0-rc.2 released
  • 2026-04-24: advisory: GitHub Security Advisory GHSA-6384-m2mw-rf54 published
  • 2026-04-30: disclosed: CVE-2026-35051 published to NVD

References

Related threats