CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54763

CVE-2026-54763: Authentication Bypass and Identity Spoofing in Traefik Middlewares via Header Normalization Discrepancies

Alon Barad
Alon Barad
Software Engineer

Aug 6, 2026·7 min read·82 visits

Executive Summary (TL;DR)

Traefik's authentication middlewares fail to strip client-supplied headers containing underscores, permitting remote unauthenticated attackers to bypass identity controls and spoof authenticated metadata on backend systems that normalize hyphens and underscores identically.

A critical authentication bypass and context spoofing vulnerability exists in Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares prior to versions 2.11.51, 3.6.22, and 3.7.6. The flaw arises because Traefik's header cleanup mechanisms rely on Go's standard library header canonicalization, which does not modify or delete headers containing underscores. Consequently, unauthenticated remote attackers can inject custom underscore-variant headers (e.g., X_Auth_User) that bypass Traefik's stripping filters and reach backend application servers. When downstream backends normalize both hyphens and underscores into the same environment variables, the attacker's spoofed identity value is processed as trusted authorization data.

Vulnerability Overview

Traefik functions as an HTTP edge proxy and load balancer designed to direct traffic and manage routing policies for cloud-native microservices. Within its architecture, the BasicAuth, DigestAuth, and ForwardAuth middlewares operate as vital access gates. These security boundaries validate client identities and credentials, then propagate trusted session identifiers (such as X-Auth-User) downstream to backend servers. This model assumes that any client-supplied authentication headers are completely sanitized or overwritten at the proxy layer before the request reaches internal systems.

The vulnerability, cataloged as CVE-2026-54763, lies in a fundamental asymmetry in character handling between Traefik's internal sanitization layer and downstream web application servers. Because the proxy does not scrub or validate underscore-variant headers, attackers can inject custom headers containing underscores that traverse the proxy intact. This issue primarily exposes backends running CGI, WSGI, or ASGI environments, which automatically normalize underscores and hyphens into identical internal representations.

This behavior matches the definitions of CWE-178 (Improper Handling of Case Sensitivity), CWE-290 (Authentication Bypass by Spoofing), and CWE-345 (Insufficient Verification of Data Authenticity). Unauthenticated remote attackers can leverage this flaw to spoof identity contexts, bypass authentication gates entirely, and obtain administrative access on downstream applications without presenting valid credentials.

Root Cause Analysis

The root cause of this vulnerability lies in the implementation of the Go standard library's net/http package and its handling of HTTP header map keys. When Go parses incoming HTTP requests, it maps headers using the textproto.CanonicalMIMEHeaderKey utility. This function normalizes headers by capitalizing characters following hyphens and converting casing, so x-auth-user or X-Auth-User resolves to the canonical key X-Auth-User. Crucially, Go's parser does not alter, normalize, or canonicalize keys containing underscores, meaning X_Auth_User remains keyed as the literal string X_Auth_User inside the request header map.

To prevent clients from injecting spoofed credentials, Traefik's authentication middlewares execute a clean-up sequence designed to remove trusted identity headers before applying the proxy's verified values. This is accomplished using Go's map deletion helper:

req.Header.Del("X-Auth-User")

Because Go uses strict, canonical string matching for this map deletion, calling Del("X-Auth-User") only matches and purges the exact key X-Auth-User. The literal key X_Auth_User is completely ignored by the deletion logic and survives the cleanup phase, remaining intact inside the forwarded HTTP request.

The final breakdown of the security boundary occurs at the backend application server. Legacy and standard application interfaces—specifically Python Gunicorn, Python uWSGI, PHP-FPM, Apache mod_cgi, and Nginx setups with underscores_in_headers on—follow CGI environment mapping specifications. These servers normalize incoming HTTP header keys into environment variables by capitalizing all characters, prefixing them with HTTP_, and converting all hyphens (-) and underscores (_) into underscores. Consequently, both the legitimate header X-Auth-User and the attacker's smuggled X_Auth_User are parsed identically as HTTP_X_AUTH_USER, allowing the attacker-controlled value to overwrite or establish the user's identity context.

Code Analysis and Patch Evaluation

Prior to the patch, Traefik relied on the standard Go Header.Del() method to sanitize authorization headers. This implementation assumed that incoming request headers would adhere to standard canonicalization rules and did not account for the loose parsing behavior of downstream CGI/WSGI environments.

To address this vulnerability, the Traefik development team introduced a commit 108a5264473a2cbc8f12d6d691a3c6553cdf2c1b that adds a custom entrypoint middleware named underscoreHeadersStrategy. This configuration supports three strategies for managing headers containing underscores: keep, delete, and reject. The two defense-oriented functions, removeHeadersWithUnderscores and rejectHeadersWithUnderscores, directly iterate through the request header map to intercept keys containing underscores.

// removeHeadersWithUnderscores removes any request header whose name contains an underscore character.
func removeHeadersWithUnderscores(h http.Handler) http.Handler {
	return http.HandlerFunc(func(rw http.ResponseWriter, req *http.Request) {
		for key := range req.Header {
			if strings.Contains(key, "_") {
				delete(req.Header, key) // Explicitly deletes underscore-variant headers
			}
		}
		h.ServeHTTP(rw, req)
	})
}
 
// rejectHeadersWithUnderscores rejects requests containing underscores with a 400 Bad Request.
func rejectHeadersWithUnderscores(h http.Handler) http.Handler {
	return http.HandlerFunc(func(rw http.ResponseWriter, req *http.Request) {
		for key := range req.Header {
			if strings.Contains(key, "_") {
				http.Error(rw, "Bad Request", http.StatusBadRequest)
				return
			}
		}
		h.ServeHTTP(rw, req)
	})
}

While this fix is highly effective at neutralizing the underscore bypass vector, it introduces a significant operational risk: the default strategy is set to keep to maintain backwards compatibility for existing infrastructure. This means that merely upgrading the binary to a patched version is insufficient; administrators must manually update their configuration to enable the delete or reject strategies. Furthermore, the fix assumes that underscores are the only character capable of causing normalization collisions. If a downstream parser normalizes other special characters, such as dots or non-ASCII characters, into hyphens, alternative bypass vectors may still exist.

Exploitation Methodology

An attacker seeking to exploit CVE-2026-54763 must identify a Traefik-proxied route protected by an identity-forwarding middleware, where the backend server uses CGI-style header normalization. The objective is to inject a custom identifier header that Traefik fails to strip but the backend processes as the authentic user identity.

To conduct the attack, the threat actor sends a crafted HTTP request directly to the Traefik entrypoint. The request contains the targeted backend's identity variable formatted with an underscore rather than a hyphen:

GET /internal-admin/settings HTTP/1.1
Host: vulnerable-app.target.local
X_Auth_User: administrative-operator

When Traefik receives this request, the ForwardAuth middleware processes authentication. If the middleware is configured to forward user information via X-Auth-User, it clears the canonical header. However, the custom header X_Auth_User bypasses this filter entirely. Traefik forwards the request downstream with the malicious header. Upon receipt, the backend environment (such as a Django app served via Gunicorn) normalizes X_Auth_User into HTTP_X_AUTH_USER. The application logic reads this environment variable and establishes a session as administrative-operator, resulting in a complete authentication bypass.

Impact Assessment

The impact of CVE-2026-54763 is critical, representing a total compromise of the authentication perimeter for systems relying on Traefik as an API gateway or ingress controller. By exploiting this flaw, unauthenticated attackers can gain arbitrary administrative privileges on internal microservices. This capability can be leveraged to view confidential database records, exfiltrate private data, or execute unauthorized operations inside the network.

Under CVSS v3.1, this vulnerability is assigned a score of 10.0 (Critical) due to the network-based attack vector, low complexity, absence of required privileges, and complete confidentiality and integrity impact on subsequent systems. Under CVSS v4.0, the vulnerability is rated 7.8 (High), reflecting a severe impact on the subsequent system (the downstream applications) rather than direct compromise of the proxy itself.

Currently, this vulnerability has a low EPSS score of 0.002, suggesting that wide-scale opportunistic exploitation is limited. However, because the technical mechanics are straightforward to reproduce and the underlying flaw resides in common open-source components, targeted exploits are highly likely. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog, and there are no reports of it being actively exploited in ransomware campaigns.

Remediation and Detection

The primary remediation step is upgrading all Traefik deployments to the officially patched releases. Vulnerable versions of the 2.x branch must be updated to version 2.11.51 or higher. Legacy 3.6.x deployments must be upgraded to 3.6.22 or higher, and active 3.7.x branches must be upgraded to 3.7.6 or higher.

Because the default strategy is configured to keep for backward compatibility, administrators must explicitly configure the entrypoint to use the delete or reject strategies. If upgrading is not immediately possible, temporary workarounds should be applied at the edge or Web Application Firewall (WAF) layer. Implementing rules that reject any incoming request carrying an underscore in its header names will neutralize the attack vector.

In the long term, software development teams must transition away from trust models that rely entirely on unauthenticated HTTP header forwarding. Downstream microservices should validate incoming requests using cryptographically signed tokens (such as JSON Web Tokens or Mutual TLS) to ensure that identity assertions originated from the trusted proxy and have not been manipulated in transit.

Official Patches

TraefikPatch commit introducing underscore headers parsing strategy.
TraefikPull Request detailing strategy options and test cases.

Technical Appendix

CVSS Score
10.0/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS Probability
0.20%
Top 90% most exploited

Affected Systems

Traefik Proxy (BasicAuth, DigestAuth, ForwardAuth middlewares)Python WSGI/ASGI application servers (Gunicorn, uWSGI)PHP-FPM and CGI-based application containersRuby Rack and thin-server deployment environments

Affected Versions Detail

Product
Affected Versions
Fixed Version
Traefik
Traefik
< 2.11.512.11.51
Traefik
Traefik
>= 3.0.0-beta1, < 3.6.223.6.22
Traefik
Traefik
>= 3.7.0-ea.1, < 3.7.63.7.6
AttributeDetail
CWE IDCWE-178, CWE-290, CWE-345
Attack VectorNetwork (Unauthenticated)
CVSS v3.1 Score10.0 (Critical)
EPSS Score0.002 (Percentile: 9.96%)
Exploit StatusProof-of-Concept Available
CISA KEV StatusNot Listed

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1548Abuse Elevation Control Mechanism
Privilege Escalation
T1027Obfuscated Files or Information
Defense Evasion
CWE-178
Improper Handling of Case Sensitivity

The software does not properly handle case or character normalization differences when parsing or validating identifier/header names, allowing authentication bypass and identity spoofing.

Known Exploits & Detection

GitHub Security Advisory Integration TestsIntegration tests within the official advisory illustrate programmatically generating underscore-variant header injection to bypass authentication boundaries.

Vulnerability Timeline

Security patch commit created internally.
2026-06-19
CVE-2026-54763 publicly disclosed and patches released.
2026-07-06
National Vulnerability Database analysis complete.
2026-07-08

References & Sources

  • [1]NVD - CVE-2026-54763 Detail
  • [2]GitHub Security Advisory GHSA-x677-9fxg-v5c5

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•31 minutes ago•CVE-2026-107377
7.5

CVE-2026-107377: Arbitrary File Write and Overwrite via Protobuf Weak Import Path Traversal in datamodel-code-generator

A path traversal vulnerability in datamodel-code-generator allows remote attackers to write or overwrite arbitrary files on the local host filesystem via a manipulated Protobuf schema containing malicious weak import paths.

Amit Schendel
Amit Schendel
2 views•5 min read
•about 2 hours ago•CVE-2026-61431
6.8

CVE-2026-61431: Arbitrary Local File Read and Path Traversal in PraisonAI ContextGatherer

PraisonAI is vulnerable to an arbitrary local file read vulnerability prior to version 4.6.78. The flaw is in the ContextGatherer component, where validation checks are executed only after files are parsed and appended to the context bundle, bypassing security constraints.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•CVE-2026-107212
7.5

CVE-2026-107212: CPU Exhaustion Denial of Service via Look-Ahead Row Parsing in Excelize

An algorithmic complexity vulnerability (CWE-770) in the Excelize library allows remote attackers to cause resource exhaustion (100% CPU usage) via a crafted Microsoft Excel spreadsheet. This occurs because the look-ahead row index parsing in Rows.Columns() fails to enforce upper boundary limits, enabling an out-of-bounds row index to trigger an infinite seek loop inside the Rows iterator.

Alon Barad
Alon Barad
10 views•6 min read
•about 3 hours ago•CVE-2026-105647
4.0

CVE-2026-105647: Server-Side Request Forgery via Favicon Probing in Ghost CMS

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability exists in Ghost CMS from version 6.54.1 to 6.65.0. The vulnerability stems from a validation bypass in the favicon resolution logic within the bookmark-fetching subsystem, which allows remote, unauthenticated attackers to trigger arbitrary HTTP requests to the local host and internal networks. This bypass circumvents the custom DNS-level IP blocklist controls configured globally in the application.

Alon Barad
Alon Barad
7 views•8 min read
•about 5 hours ago•CVE-2026-106450
5.3

CVE-2026-106450: Denial of Service via Eager Resource Allocation in lz4-java LZ4FrameInputStream

A resource allocation vulnerability (CWE-770) in lz4-java before version 1.11.4 allows an unauthenticated remote attacker to trigger CPU exhaustion and high garbage collection overhead by streaming empty concatenated LZ4 frames.

Alon Barad
Alon Barad
12 views•8 min read
•about 6 hours ago•CVE-2026-106449
3.7

CVE-2026-106449: Stack Overflow via Uncontrolled Recursion in yawkat lz4-java

A Denial of Service (DoS) vulnerability exists in the yawkat fork of lz4-java prior to version 1.11.4. Under specific non-default configurations (stopOnEmptyBlock = false), parsing crafted streams with a large sequence of contiguous empty LZ4 blocks triggers uncontrolled recursion inside the LZ4BlockInputStream.refill() method, causing stack exhaustion and thread termination.

Alon Barad
Alon Barad
7 views•6 min read