Skip to content
VulniPulse
Advisory severityCritical10.0Vendor: HighRed Hat Linux

Critical [CVE-2026-54763] Identity spoofing via improper header handling in authentication middlewares

This critical-severity Red Hat Linux advisory covers CVE-2026-54763 affecting Red Hat OpenShift Dev Spaces.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-54763 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxUnclassified
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

Traefik is an HTTP reverse proxy and load balancer. Prior to v2.11.51, v3.6.22, and v3.7.6, Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares strip canonical-cased spoofed identity headers before writing Traefik's own value, but do not account for underscore-variant header names, which many backends normalize identically to dashed forms.

An attacker able to reach a protected route can inject an underscore-variant header that survives Traefik's stripping and reaches the backend alongside, or on the unauthenticated ForwardAuth authResponseHeaders path instead of, the value Traefik intended to set, spoofing identity or authorization context.

This issue is fixed in versions v2.11.51, v3.6.22, and v3.7.6. This allows a remote attacker to inject a specially crafted header that bypasses Traefik's security mechanisms.

As a result, the attacker can spoof identity or authorization context to the backend, potentially gaining unauthorized access to protected resources. This can lead to identity spoofing or unauthorized access to backend services, as Traefik fails to properly strip these headers before forwarding them.

The vulnerability is significant because many backend systems normalize these header forms, making exploitation feasible in typical deployments. Red Hat severity: Important — CVSS 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Weakness: CWE-178.

Affected versions
  • < 11.51
  • < 6.22
  • < 7.6

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Fixed versions
  • 11.51
  • 6.22

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Mitigation

Upgrade to a fixed release: 11.51, 6.22. That is the remediation for this advisory.

The vendor advisory may list additional interim mitigations or workarounds not captured here — review it before change work.

Official advisory · high-confidence parse· fetched 15 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.