{"id":"CVE-2026-54764","aliases":["GHSA-3q9r-p662-5j8m","GO-2026-6202"],"url":"https://o3.security/vulnerability/CVE-2026-54764","summary":"ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false","details":"Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's ForwardAuth middleware, even when configured with trustForwardHeader: false, derives the X-Forwarded-Port header sent to the authentication service from the original incoming request instead of the sanitized forwarded request. As a result, an unauthenticated remote attacker can inject an X-Forwarded-Proto: https header over a plain HTTP connection and cause Traefik to forward X-Forwarded-Port: 443 to the authentication service, bypassing port-based authorization checks. This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6.","published":"2026-07-06T20:20:29.345Z","modified":"2026-09-09T18:26:45.036812047Z","cvss":null,"epss":{"score":0.00233,"percentile":0.14421,"asOf":"2026-08-23"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Go","name":"github.com/traefik/traefik/v2","fixedVersion":"2.11.51"},{"ecosystem":"Go","name":"github.com/traefik/traefik/v3","fixedVersion":"3.6.22"},{"ecosystem":"Go","name":"github.com/traefik/traefik/v3","fixedVersion":"3.7.6"},{"ecosystem":"Go","name":"github.com/traefik/traefik","fixedVersion":null}],"fix":{"url":"https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d","label":"traefik/traefik@7ae92d8"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54764.json"},{"type":"ADVISORY","url":"https://github.com/traefik/traefik/security/advisories/GHSA-3q9r-p662-5j8m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54764"},{"type":"FIX","url":"https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d"},{"type":"FIX","url":"https://github.com/traefik/traefik/pull/13344"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T18:26:45.036812047Z"}}