Insufficient Verification of Data Authenticity Affecting github.com/traefik/traefik/v3/pkg/middlewares/auth package, versions >=3.0.0 <3.6.22>=3.7.0 <3.7.6


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.28% (20th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-GOLANG-GITHUBCOMTRAEFIKTRAEFIKV3PKGMIDDLEWARESAUTH-17872272
  • published6 Jul 2026
  • disclosed6 Jul 2026
  • creditUnknown

Introduced: 6 Jul 2026

CVE-2026-54764  (opens in a new tab)
CWE-345  (opens in a new tab)

How to fix?

Upgrade github.com/traefik/traefik/v3/pkg/middlewares/auth to version 3.6.22, 3.7.6 or higher.

Overview

Affected versions of this package are vulnerable to Insufficient Verification of Data Authenticity in the ForwardAuth process when trustForwardHeader is set to false. An attacker can bypass port-based authorization checks by injecting a crafted X-Forwarded-Proto header over an unencrypted HTTP connection, causing the system to forward an incorrect X-Forwarded-Port value to the authentication service.

CVSS Base Scores

version 4.0
version 3.1