Case-Sensitive Bypass in Connection Header Allows Removal of X-Forwarded Headers
Upstream fixed versions: Traefik: v2.11.38; Traefik: v3.6.9
details
- Finding IDs
- F-TRAEFIK-003
- CVE
- CVE-2026-29054
- GHSA
- GHSA-92mv-8f8w-wq52
- Status
- patched
- Fixed in
- Traefik: v2.11.38; Traefik: v3.6.9
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- CVE registry state
- PUBLISHED
- CVE state checked
- Upstream title
- Case-Sensitive Bypass in Connection Header Allows Removal of X-Forwarded Headers
- Upstream CWE
- CWE-178
- Upstream publication
- Upstream updated
- Metadata fetched
- Upstream fixed versions
- Traefik: v2.11.38; Traefik: v3.6.9
- Upstream affected ranges
- Traefik: >= v2.11.9, <= v2.11.37; Traefik: >= v3.1.3, <= v3.6.8
- Upstream @1seal credit
- @1seal: reporter (accepted)
F-TRAEFIK-003: Input / state handling. Case handling leaves hop-by-hop headers inconsistently processed. Reviewed 24 Sep 2026. Mechanism assessed by 1seal.
Mechanism source for F-TRAEFIK-003
Security area (1seal assessment): Semantics. Case-dependent Connection header processing gives inconsistent meaning to forwarded-header removal, a request-interpretation boundary. Reviewed 24 Sep 2026.