Exposure of Data Element to Wrong Session in Traefik - #VU153910
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to read victim-only data and perform actions in the victim's name without presenting credentials.
The vulnerability exists due to improper isolation of connection-bound authentication identities in the FastProxy backend connection pool when dispatching requests to plain HTTP backends using NTLM or Negotiate authentication. A remote attacker can send requests through a new frontend connection that reuses a backend connection on which a victim has already authenticated to read victim-only data and perform actions in the victim's name without presenting credentials.
Exploitation requires experimental.fastProxy to be enabled and backend keep-alive to be in use. The default proxy implementation is not affected.