Sploitus

CVE-2026-54764

No indexed exploits for CVE-2026-54764 yet

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.

Affected products
Traefik
Traefik
< 2.11.51, 3.6.22, 3.7.6
Fix
Available
CVSS 4.0
6.9 MEDIUM
CVSS 3.1
5.8 MEDIUM
EPSS
0.2% (14th percentile)
Weakness
CWE-345
NVD status
Analyzed
Published
2026-07-06
CVE-2026-54764 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2026-54764 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2026-54764 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.