Executive brief
Traefik, a popular tool for managing web traffic and load balancing, contains a flaw in how it handles custom error pages. When a website encounters an error, Traefik may accidentally send sensitive user information—such as login tokens and session cookies—to the service responsible for displaying the error page. This could allow unauthorized internal services or third-party error handlers to see private user credentials they were never intended to access.
Technical details
An information disclosure vulnerability exists in Traefik's 'errors' (custom error pages) middleware due to improper header sanitization. When a backend service returns an HTTP status code within a configured error range, the middleware generates a new request to the designated error service. By default, the implementation uses 'utils.CopyHeaders' to clone the entire original request header map into the new request, rather than forwarding only the 'Host' header as documented. This results in the transmission of sensitive 'Authorization' and 'Cookie' headers to the error service. The issue is fixed in versions 2.11.44, 3.6.15, and 3.7.0-rc.3 by introducing the 'errorRequestHeaders' option to control header forwarding.
Affected products
- Traefik Labs Traefik < 2.11.44, < 3.6.15, < 3.7.0-rc.3
Timeline
- 2026-04-29: patched: Fixes released in versions 2.11.44 and 3.6.15
- 2026-05-04: advisory: GitHub Security Advisory GHSA-p6hg-qh38-555r published
- 2026-05-15: disclosed: CVE-2026-41181 published to NVD