Vulnerability GHSA-6384-m2mw-rf54: Information

Description

Traefik's ForwardAuth trustForwardHeader=false allows spoofed X-Forwarded-Prefix to bypass authentication

Severity: HIGH (7.8)
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:L/SA:N
Severity: (0.0)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Published: April 24, 2026
Modified: May 7, 2026
Error type identifier: CWE-345

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
traefiksisyphus3.6.15-alt13.6.17-alt1ALT-PU-2026-7142-5417190Fixed
traefiksisyphus_riscv643.6.15-alt13.6.17-alt1ALT-PU-2026-7534-1-Fixed
traefiksisyphus_loongarch643.6.15-alt13.6.17-alt1ALT-PU-2026-7499-1-Fixed
traefikp113.6.15-alt13.6.17-alt1ALT-PU-2026-7164-5417230Fixed
traefikc10f23.6.15-alt13.6.17-alt1ALT-PU-2026-7154-5417229Fixed

Affected packages

Ecosystem
Name
Affected versions
Patched versions
Gogithub.com/traefik/traefik/v3
>=3.7.0-ea.1, <3.7.0-rc.2
>=3.0.0-beta1, <3.6.14
3.7.0-rc.2
3.6.14
Gogithub.com/traefik/traefik/v2
<2.11.43
2.11.43
Gogithub.com/traefik/traefik
<=1.7.34
None

References to Advisories, Solutions, and Tools