Skip to main content
Version: v1.1.x

CVE-2026-35051

CVE Details

Visit the official vulnerability details page for CVE-2026-35051 to learn more.

Initial Publication

04/30/2026

Last Update

05/01/2026

Third Party Dependency

github.com/traefik/traefik/v3

NIST CVE Summary

Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustForwardHeader=false is configured and Traefik is deployed behind a trusted upstream proxy. This issue has been patched in versions 2.11.43, 3.6.14, and 3.7.0-rc.2.

CVE Severity

10

Our Official Summary

Investigation is ongoing to determine how this vulnerability affects our products.

Status

Analyzed

Affected Products & Versions

VersionPaletteAIPaletteAI VerteX
1.1.0⚠️ Impacted⚠️ Impacted

Revision History

No revisions available.