PT-2026-28482 · Traefik · Traefik

0Xvijay

·

Published

2025-03-27

·

Updated

2026-04-07

·

CVE-2026-33433

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Traefik versions prior to 2.11.42 Traefik versions prior to 3.6.12 Traefik versions prior to 3.7.0-ea.3
Description Traefik, an HTTP reverse proxy and load balancer, is susceptible to an identity impersonation issue. When the headerField configuration option is used with a non-canonical HTTP header name (for example, x-auth-user instead of X-Auth-User), an authenticated attacker can inject a canonical version of that header. This allows the attacker to impersonate any identity to the backend service. The backend receives two header entries, with the attacker-injected canonical version being read first, overriding Traefik's non-canonical write. This issue affects the Basic and Digest authentication middlewares. The vulnerability occurs because Traefik writes the authenticated username using a non-canonical map key, creating a separate header entry instead of overwriting the attacker's canonical one.
Recommendations Traefik versions prior to 2.11.42 should be updated to version 2.11.42 or later. Traefik versions prior to 3.6.12 should be updated to version 3.6.12 or later. Traefik versions prior to 3.7.0-ea.3 should be updated to version 3.7.0-ea.3 or later.

Exploit

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2026-05930
CVE-2026-33433
ECHO-F91F-26EA-BBF3
GHSA-QR99-7898-VR7C
GO-2026-4893
SUSE-SU-2026:1205-1

Affected Products

Traefik