VDB
CVE-2026-54764
CVE-2026-54764
PUBLISHED
CVSS 6.900000095367432 MEDIUM
Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false
EPSS 0.23% · 14.1th percentile
Risk Scores
CVSS 4.0
6.900000095367432
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N
EPSS Score
0.23%
14.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| github.com | traefik/traefik/v2 | 0, 0, 0 |
| traefik | traefik | >= 3.7.0, < 3.7.6, >= 3.0.0, < 3.6.22, < 2.11.51 |
| github.com | traefik/traefik/v3 | 0, 0, 3.7.0 |
| github.com | traefik/traefik | 0, 0, 0 |
| alpine | traefik | 0, 0, 0 |
Timeline
- Jul 6, 2026 CVE Published
- Jul 7, 2026 EPSS Score
- Jul 7, 2026 Coalition ESS Score
- Jul 9, 2026 Security Advisory
- Aug 7, 2026 EPSS Score
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-54764 advisory
- https://github.com/advisories/GHSA-3q9r-p662-5j8m advisory
- https://github.com/traefik/traefik/security/advisories/GHSA-3q9r-p662-5j8m url
- https://github.com/traefik/traefik/pull/13344 patch
- https://github.com/traefik/traefik/commit/7ae92d8c2c10ac04ef5a03df0ed5019ce0f44b2d patch
- https://github.com/traefik/traefik/releases/tag/v2.11.51 url
- https://github.com/traefik/traefik/releases/tag/v3.6.22 url
- https://github.com/traefik/traefik/releases/tag/v3.7.6 url