CVE-2026-54764
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.
- Affected products
- Traefik
- Traefik
- < 2.11.51, 3.6.22, 3.7.6
- Fix
- Available
- CVSS 4.0
- 6.9 MEDIUM
- CVSS 3.1
- 5.8 MEDIUM
- EPSS
- 0.2% (14th percentile)
- Weakness
- CWE-345
- NVD status
- Analyzed
- Published
- 2026-07-06
No indexed exploits for CVE-2026-54764 yet
Our index is partial: it proves presence, never absence
No exploit for CVE-2026-54764 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.