All verified exploits

CVE-2026-29054 X-Forwarded Header Bypass via Connection Token Case Mismatch

Deterministic high Traefik Added cve-verified-cve-2026-29054

Detects Traefik instances where lowercase Connection header tokens bypass the case-sensitive protection check, allowing attackers to strip Traefik-managed identity headers (X-Real-Ip, X-Forwarded-Host, etc.) from proxied requests. Versions 2.11.9–2.11.37 and 3.1.3–3.6.8 are affected.

Is your app exploitable through CVE-2026-29054?

Scan your domain free