CVE-2026-33433 is a critical header injection vulnerability affecting Traefik versions prior to 2.11.42, 3.6.11, and 3.7.0-ea.3. An authenticated attacker can exploit misconfigured non-canonical header fields to inject their own canonical header, enabling impersonation of any identity to the backend. Rated 8.8 HIGH on CVSS, this flaw presents a severe risk with high impact on confidentiality, integrity, and availability, requiring only low privileges and network access. While no public exploit code or active exploitation in the wild has been confirmed, it is included on the Hot List, indicating its significant potential risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.11.42CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | ||
>= 3.0.0, < 3.6.12CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | ||
3.7.0CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:3.7.0:ea1:*:*:*:*:*:* | ||
3.7.0CPE matchmatch criteria | cpe:2.3:a:traefik:traefik:3.7.0:ea2:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.