CVE-2026-35051 Details
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
An authentication bypass vulnerability has been identified in Traefik's ForwardAuth middleware. This issue affects Traefik versions prior to 2.11.43, 3.6.14, and 3.7.0-rc.2. The vulnerability arises when trustForwardHeader is set to false, and Traefik is deployed behind a trusted upstream proxy. In this configuration, while standard X-Forwarded headers are properly managed, the X-Forwarded-Prefix header is not stripped or rebuilt. This oversight allows attackers to spoof prefix values, potentially bypassing authentication and gaining unauthorized access to protected backend routes.
Users can upgrade to Traefik versions 2.11.43, 3.6.14, or 3.7.0-rc.2 to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:21772 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-35051 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2464235 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-35051.json | redhat-SADP | |
| https://github.com/traefik/traefik/releases/tag/v2.11.43 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/releases/tag/v3.6.14 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/releases/tag/v3.7.0-rc.2 | [email protected] | ProductRelease Notes |
| https://github.com/traefik/traefik/security/advisories/GHSA-6384-m2mw-rf54 | [email protected] | ExploitPatchVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-345 | Insufficient Verification of Data Authenticity | [email protected] |
| CWE-501 | Trust Boundary Violation | redhat-SADP |
Affected Products
| Product | Versions |
|---|---|
| traefik traefik | < 2.11.43 >= 3.0.0, < 3.6.14 3.7.0 ea1 3.7.0 ea2 3.7.0 ea3 3.7.0 rc1 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 1, 2026 | Initial Analysis | [email protected] |
| Apr 30, 2026 | New CVE Received | [email protected] |