Traefik's `ForwardAuth` and snippet-based authentication middleware has a high severity authentication bypass vulnerability because it does not sanitize header aliases with underscores, allowing attackers to spoof trust context and bypass authentication on protected routes.
PoC
Traefik +1
authentication-bypass
header-injection
forwarded-headers
2r
1t
2c
updated