CVE-2026-33433HIGH 8.8EPSS p35.7%

CVE-2026-33433CVE-2026-33433

Description

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.42, 3.6.11, and 3.7.0-ea.3, when `headerField` is configured with a non-canonical HTTP header name (e.g., `x-auth-user` instead of `X-Auth-User`), an authenticated attacker can inject their own canonical version of that header to impersonate any identity to the backend. The backend receives two header entries — the attacker-injected canonical one is read first, overriding Traefik's non-canonical write. Versions 2.11.42, 3.6.11, and 3.7.0-ea.3 patch the issue.

Scoring

CVSS 3.18.8 (HIGH)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS0.45% probability of exploitation · percentile 35.7% · 2026-06-19T12:03:05Z
Published2026-03-27
Last modified2026-04-03

Underlying weaknesses· 1

CWE-290

References

  1. https://github.com/traefik/traefik/releases/tag/v2.11.42
  2. https://github.com/traefik/traefik/releases/tag/v3.6.11
  3. https://github.com/traefik/traefik/releases/tag/v3.7.0-ea.3
  4. https://github.com/traefik/traefik/security/advisories/GHSA-qr99-7898-vr7c

1

TypeTargetConfidenceTier
WeaknessAuthentication Bypass by Spoofingcwe-2900%live

Related by meaning· 6

Nearest entities by semantic similarity across the cs-graph corpus.

CVE
CVE-2026-39858
CVE
CVE-2026-35051
CVE
CVE-2026-40912
CVE
CVE-2026-44774
CVE
CVE-2025-32431
CVE
CVE-2025-47952
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.