THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-3q9r-p662-5j8m (medium) — Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

[GHSA] GHSA-3q9r-p662-5j8m (medium) — Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

highgithub_advisoriesPublished 2026-08-06

GHSA-3q9r-p662-5j8m Severity: medium CVE: CVE-2026-54764

Traefik: ForwardAuth middleware leaks X-Forwarded-Port spoofing via untrusted X-Forwarded-Proto when trustForwardHeader=false

## Summary

There is a medium severity vulnerability in Traefik's ForwardAuth middleware. Even when configured with `trustForwardHeader: false`, Traefik derives the `X-Forwarded-Port` header sent to the authenticati

Indicators of compromise

Original source: https://github.com/advisories/GHSA-3q9r-p662-5j8m