VDB

GO-2026-4597

GO-2026-4597 PUBLISHED

traefik CVE-2024-45410 fix bypass: lowercase `Connection` tokens can delete traefik-managed forwarded identity headers (for example, `X-Real-Ip`) in github.com/traefik/traefik

Affected Products

VendorProductVersions
github.comtraefik/traefik0, 0
github.comtraefik/traefik/v22.11.9, 2.11.9
github.comtraefik/traefik/v33.1.3, 3.1.3

Timeline

  • Mar 10, 2026 CVE Published
  • Apr 16, 2026 CVE Updated
  • May 1, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›