CVE-2026-35051: Traefik

Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

Affected products

  • Traefik Traefik: before 2.11.43 (fixed in 2.11.43); from 3.0.0, before 3.6.14 (fixed in 3.6.14); version 3.7.0 only

Published 2026-04-30. Last modified 2026-07-15.