Traefik Traefik — CVE-2026-54763 (Critical)
Summary
Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms. An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik int
Why it matters
This CVE carries a CRITICAL severity rating (CVSS 10.0) in Traefik Traefik. Patch or mitigate promptly. EPSS percentile: 19%.
Operator check
Review CVE-2026-54763 in your asset inventory. Apply patches per vendor guidance and verify Traefik is not exposed. CVSS score: 10.0. EPSS probability: 0.3%; percentile: 19%.
Sources
PatchBrief uses public sources. It does not scan environments, verify exposure, or replace vendor guidance.