Traefik Traefik — CVE-2026-54763 (Critical)

Date Jul 6, 2026
Type Vendor advisory
Signal Critical vendor advisory
Vendor / Product Traefik · Traefik
CVE CVE-2026-54763
Critical vendor advisory CVE-2026-54763

Summary

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik int

Why it matters

This CVE carries a CRITICAL severity rating (CVSS 10.0) in Traefik Traefik. Patch or mitigate promptly. EPSS percentile: 19%.

Operator check

Review CVE-2026-54763 in your asset inventory. Apply patches per vendor guidance and verify Traefik is not exposed. CVSS score: 10.0. EPSS probability: 0.3%; percentile: 19%.

Sources

PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.