Traefik是Traefik公司开源的一款反向代理与负载均衡工具。 Traefik 2.11.51之前版本、3.6.22之前版本和3.7.6之前版本存在输入验证错误漏洞,该漏洞源于ForwardAuth middleware从原始请求而不是清理后的转发请求中获取X-Forwarded-Port标头,导致未经身份验证的远程攻击者可以通过纯HTTP连接注入X-Forwarded-Proto: https标头,使Traefik向认证服务转发X-Forwarded-Port: 443,绕过基于端口的授权检查。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-54763 | Traefik: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / Forw | |
| CVE-2026-54765 | Traefik: Gateway HTTPRoute backendRef filters can leak backend context across routes shari |
No comments yet