CVE-2026-35051: Traefik
Critical severity, CVSS 10.0. EPSS: 0.3% chance of exploitation in the next 30 days.
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.
Affected products
- Traefik Traefik: before 2.11.43 (fixed in 2.11.43); from 3.0.0, before 3.6.14 (fixed in 3.6.14); version 3.7.0 only
Published 2026-04-30. Last modified 2026-07-15.