Traefik disclosed and patched multiple vulnerabilities that let unauthenticated attackers bypass authentication and authorization controls by abusing forwarded-header handling. The most severe issue, CVE-2026-54763 with a CVSS 10.0, allows BasicAuth, DigestAuth, and ForwardAuth protections to be bypassed through underscore-variant header injection that can spoof identity or authorization context. Two related flaws, CVE-2026-54764 and CVE-2026-54765, respectively enable bypass of port-based authorization checks in ForwardAuth via injected X-Forwarded-Proto values and leak backend context across Kubernetes Gateway API routes that share the same Service:port.
The disclosures build on earlier high-severity Traefik ForwardAuth bugs, CVE-2026-35051 and CVE-2026-39858, which exposed protected routes when Traefik was deployed behind an upstream proxy or when downstream systems normalized underscore-form headers such as X_Forwarded_Proto and X_Forwarded_User. Affected versions span Traefik v2 and v3 releases prior to the vendor fixes, including 2.11.51, 3.6.22, and 3.7.6 for the latest issues, with the newer bugs described as evidence that earlier header-sanitization fixes were incomplete. The flaws put services commonly protected by ForwardAuth—such as Grafana, Kibana, Portainer, Kubernetes Dashboard, internal APIs, and admin panels—at risk, although no public exploits were reported at disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Later reporting stated that CVE-2026-54763 showed the initial underscore-header fix from the April 2026 issues was incomplete. This linked the new critical auth-bypass bug to the earlier ForwardAuth header-sanitization weaknesses.
The April 2026 disclosures affected Traefik v2 before 2.11.43, v3 before 3.6.14, and v3.7 before 3.7.0-rc.2, indicating patched releases at those versions and later. The fixes addressed ForwardAuth authentication bypass conditions tied to forwarded-header handling.
Two high-severity Traefik ForwardAuth vulnerabilities, CVE-2026-35051 and CVE-2026-39858, were disclosed in April 2026. The flaws allow unauthenticated attackers to bypass authentication via unsanitized X-Forwarded-Prefix handling and underscore-form forwarded headers.
At the time the July vulnerability cluster was disclosed, the reporting stated there were no known public exploits available. This accompanied disclosure of the patched CVEs affecting Traefik authentication and routing behavior.
Traefik released emergency security updates for CVE-2026-54763, CVE-2026-54764, and CVE-2026-54765 affecting versions prior to 2.11.51, 3.6.22, and 3.7.6. The flaws included authentication bypass, port-based authorization bypass, and backend context leakage in Kubernetes Gateway API deployments.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.