Improper Authentication in Traefik - #VU153912
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to impersonate a legitimate client and perform reads or writes with that client's permissions.
The vulnerability exists due to improper authentication isolation in Traefik's globally shared backend connection pool when reusing authenticated backend connections. A remote attacker can send requests over a separate frontend connection that is assigned a victim-authenticated backend socket to impersonate a legitimate client and perform reads or writes with that client's permissions.
Exploitation requires a connection-bound NTLM or SPNEGO/Kerberos Negotiate backend and a legitimate client that sends a valid Authorization: Negotiate token on its first request. The ordinary challenge-first authentication flow is not affected. The issue occurs on HTTP/1.1 and HTTP/2 frontend connections.