Junglewise Threat Intelligence

CVE-2026-39858: Traefik auth bypass in ForwardAuth middleware via header spoofing

CVE-2026-39858 · Severity: critical · CVSS 10 · Published 2026-04-30

Technologies: github.com/traefik/traefik/v3 (Go), github.com/traefik/traefik/v2 (Go), github.com/traefik/traefik (Go). Vendors: Go, Traefik Labs.

Executive brief

Traefik is a popular open-source tool used to manage and route web traffic to different services. A security flaw in how it handles web request headers allows attackers to bypass authentication checks on protected routes. This could allow an unauthorized person to access sensitive internal data or administrative functions without providing a valid password or credentials.

Technical details

An authentication bypass vulnerability exists in Traefik's ForwardAuth and snippet-based authentication middleware due to inconsistent header sanitization. Traefik's sanitization logic only targets canonical header names (using dashes, e.g., X-Forwarded-Proto) and fails to strip or normalize alias variants using underscores (e.g., X_Forwarded_Proto). If an authentication backend normalizes these underscore-based headers, an unauthenticated remote attacker can inject spoofed trust context, such as a trusted host or protocol scheme. This allows the attacker to bypass authentication on protected routes. The issue is patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

Affected products

  • Traefik Labs Traefik < 2.11.43, >= 3.0.0-beta1, < 3.6.14, >= 3.7.0-ea.1, < 3.7.0-rc.2

Timeline

  • 2026-04-22: patched: Fixes released in versions 2.11.43, 3.6.14, and 3.7.0-rc.2
  • 2026-04-24: advisory: GitHub Security Advisory GHSA-5m6w-wvh7-57vm published
  • 2026-04-30: disclosed: CVE-2026-39858 published to NVD

References

Related threats