Executive brief
Traefik is a popular open-source tool used to manage and route web traffic to different services. A security flaw in how it handles web request headers allows attackers to bypass authentication checks on protected routes. This could allow an unauthorized person to access sensitive internal data or administrative functions without providing a valid password or credentials.
Technical details
An authentication bypass vulnerability exists in Traefik's ForwardAuth and snippet-based authentication middleware due to inconsistent header sanitization. Traefik's sanitization logic only targets canonical header names (using dashes, e.g., X-Forwarded-Proto) and fails to strip or normalize alias variants using underscores (e.g., X_Forwarded_Proto). If an authentication backend normalizes these underscore-based headers, an unauthenticated remote attacker can inject spoofed trust context, such as a trusted host or protocol scheme. This allows the attacker to bypass authentication on protected routes. The issue is patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Affected products
- Traefik Labs Traefik < 2.11.43, >= 3.0.0-beta1, < 3.6.14, >= 3.7.0-ea.1, < 3.7.0-rc.2
Timeline
- 2026-04-22: patched: Fixes released in versions 2.11.43, 3.6.14, and 3.7.0-rc.2
- 2026-04-24: advisory: GitHub Security Advisory GHSA-5m6w-wvh7-57vm published
- 2026-04-30: disclosed: CVE-2026-39858 published to NVD
References
- https://github.com/traefik/traefik/releases/tag/v2.11.43
- https://github.com/traefik/traefik/releases/tag/v3.6.14
- https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2
- https://github.com/traefik/traefik/security/advisories/GHSA-5m6w-wvh7-57vm
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/security/cve/CVE-2026-39858
- https://bugzilla.redhat.com/show_bug.cgi?id=2464234