Executive brief
Traefik, a popular tool used to manage and route web traffic, contains a security flaw that could allow unauthorized users to bypass login requirements. When Traefik is set up behind another proxy server, an attacker can send specially crafted web requests that trick the system into granting access to protected areas. This could lead to the exposure of sensitive customer data or unauthorized control over internal business applications.
Technical details
An authentication bypass vulnerability exists in Traefik's ForwardAuth middleware due to insufficient verification of data authenticity. When Traefik is configured with 'trustForwardHeader=false' and deployed behind a trusted upstream proxy, the middleware fails to strip or rebuild the 'X-Forwarded-Prefix' header before sending subrequests to the authentication service. While other 'X-Forwarded-*' headers are correctly handled, the 'X-Forwarded-Prefix' remains attacker-controlled. If the downstream authentication service relies on this header to make authorization or routing decisions, a remote, unauthenticated attacker can spoof the prefix to bypass access controls. The issue is patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Affected products
- Traefik Labs Traefik < 2.11.43, >= 3.0.0-beta1 < 3.6.14, >= 3.7.0-ea.1 < 3.7.0-rc.2
- Red Hat Red Hat OpenShift Dev Spaces 3.28 3.28
Timeline
- 2026-04-22: patched: Fixed versions 2.11.43, 3.6.14, and 3.7.0-rc.2 released
- 2026-04-24: advisory: GitHub Security Advisory GHSA-6384-m2mw-rf54 published
- 2026-04-30: disclosed: CVE-2026-35051 published to NVD
References
- https://github.com/traefik/traefik/releases/tag/v2.11.43
- https://github.com/traefik/traefik/releases/tag/v3.6.14
- https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2
- https://github.com/traefik/traefik/security/advisories/GHSA-6384-m2mw-rf54
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/security/cve/CVE-2026-35051
- https://bugzilla.redhat.com/show_bug.cgi?id=2464235