CVE-2026-35051
Critical · CVSS 10.0Traefik — Authentication Bypass via Insufficient Verification of Data Authenticity (ForwardAuth middleware trust header bypass)
- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- other
- CWE-345, CWE-501
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Search profile — drives PoC discovery
Symbols ForwardAuthtrustForwardHeaderX-Forwarded-ForX-Forwarded-UriX-Forwarded-HostforwardAuthmiddlewareupstream proxyGHSA-6384-m2mw-rf54
Keywords CVE-2026-35051Traefik ForwardAuth bypasstrustForwardHeader false bypassTraefik authentication bypassGHSA-6384-m2mw-rf54Traefik middleware auth bypassTraefik forward auth trusted proxyCWE-345 TraefikCWE-501 Traefik
Versions: < 2.11.43, < 3.6.14, < 3.7.0-rc.2
References
- https://github.com/traefik/traefik/releases/tag/v2.11.43
- https://github.com/traefik/traefik/releases/tag/v3.6.14
- https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2
- https://github.com/traefik/traefik/security/advisories/GHSA-6384-m2mw-rf54
- https://access.redhat.com/errata/RHSA-2026:21772
- https://access.redhat.com/security/cve/CVE-2026-35051
- https://bugzilla.redhat.com/show_bug.cgi?id=2464235
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35051.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-07-01T06:30:14.000Z