Authentication Bypass by Spoofing in Traefik - #VU146000

 

Authentication Bypass by Spoofing in Traefik - #VU146000

Published: August 27, 2026


Vulnerability identifier: #VU146000
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to spoof identities.

The vulnerability exists due to authentication bypass by spoofing in ForwardAuth-managed request headers when handling client-supplied header aliases that collapse to the same backend variable name. A remote user can send a specially crafted request with a dot-form header alias to spoof identities.

Exploitation requires the request to be permitted by ForwardAuth first, and impacts backends that normalize distinct header names into the same variable.


Affected software

Traefik

Remediation

Install security update from vendor's website.

Traefik - addressed in versions 2.11.56, 3.7.12

External References

Related Security Bulletins