Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-6384-m2mw-rf54 | Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication |
Sat, 09 May 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-501 | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Fri, 01 May 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 01 May 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* cpe:2.3:a:traefik:traefik:3.7.0:ea1:*:*:*:*:*:* cpe:2.3:a:traefik:traefik:3.7.0:ea2:*:*:*:*:*:* cpe:2.3:a:traefik:traefik:3.7.0:ea3:*:*:*:*:*:* cpe:2.3:a:traefik:traefik:3.7.0:rc1:*:*:*:*:*:* |
|
| Metrics |
cvssV3_1
|
Thu, 30 Apr 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Traefik
Traefik traefik |
|
| Vendors & Products |
Traefik
Traefik traefik |
Thu, 30 Apr 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2. | |
| Title | Traefik: ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass auth | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-05-01T21:20:11.714Z
Reserved: 2026-03-31T21:06:06.429Z
Link: CVE-2026-35051
Updated: 2026-05-01T21:20:07.596Z
Status : Analyzed
Published: 2026-04-30T21:16:32.047
Modified: 2026-05-01T17:45:41.300
Link: CVE-2026-35051
OpenCVE Enrichment
Updated: 2026-05-09T02:15:06Z
Github GHSA