<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 15:44:19 +0000</lastBuildDate>
    <item>
      <title>certfr-2024-avi-1029 — Une vulnérabilité a été découverte dans Traefik. Elle permet à un attaquant de provoquer un contournement de la politiq…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-1029</link>
      <description>certfr-2024-avi-1029</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-1029</guid>
    </item>
    <item>
      <title>EUVD-2026-205252</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-205252</link>
      <description>EUVD-2026-205252</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-205252</guid>
    </item>
    <item>
      <title>fkie_cve-2024-52003</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-52003</link>
      <description>&lt;p&gt;Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik (pronounced traffic) is an HTTP reverse proxy and load balancer. There is a vulnerability in Traefik that allows the client to provide the X-Forwarded-Prefix header from an untrusted source. This issue has been addressed in versions 2.11.14 and 3.2.1. Users are advised to upgrade. There are no known workarounds for this vulnerability.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-52003</guid>
    </item>
    <item>
      <title>GHSA-h924-8g65-j9wg — Traefik's X-Forwarded-Prefix Header still allows for Open Redirect</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-h924-8g65-j9wg</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;There is a vulnerability in Traefik that allows the client to provide the `X-Forwarded-Prefix` header from an untrusted source.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.14
- https://github.com/traefik/traefik/releases/tag/v3.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;
### Summary
The previously reported open redirect ([GHSA-6qq8-5wq3-86rp](https://github.com/traefik/traefik/security/advisories/GHSA-6qq8-5wq3-86rp)) is not fixed correctly. The safePrefix function can be tricked to return an absolute URL.&lt;/p&gt;
&lt;p&gt;### Details
The Traefik API [dashboard component](https://github.com/traefik/traefik/blob/master/pkg/api/dashboard/dashboard.go) tries to validate that the value of the header X-Forwarded-Prefix is a site relative path:
```go
http.Redirect(resp, req, safePrefix(req)+&amp;#34;/dashboard/&amp;#34;, http.StatusFound)
```&lt;/p&gt;
&lt;p&gt;```go
func safePrefix(req *http.Request) string {
	prefix := req.Header.Get(&amp;#34;X-Forwarded-Prefix&amp;#34;)
	if prefix == &amp;#34;&amp;#34; {
		return &amp;#34;&amp;#34;
	}&lt;/p&gt;
&lt;p&gt;parse, err := url.Parse(prefix)
	if err != nil {
		return &amp;#34;&amp;#34;
	}&lt;/p&gt;
&lt;p&gt;return parse.Path
}
```&lt;/p&gt;
&lt;p&gt;### PoC
An attacker can bypass this by sending the following payload:&lt;/p&gt;
&lt;p&gt;```bash
curl -v &amp;#39;http://traefik.localhost&amp;#39; -H &amp;#39;X-Forwarded-Prefix: %0d//a.com&amp;#39;
[...]
&amp;gt; HTTP/1.1 302 Found
&amp;gt; Location: //a.com/dashboard/
```&lt;/p&gt;
&lt;p&gt;or sim…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;There is a vulnerability in Traefik that allows the client to provide the `X-Forwarded-Prefix` header from an untrusted source.&lt;/p&gt;
&lt;p&gt;### Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.14
- https://github.com/traefik/traefik/releases/tag/v3.2.1&lt;/p&gt;
&lt;p&gt;### Workarounds&lt;/p&gt;
&lt;p&gt;No workaround.&lt;/p&gt;
&lt;p&gt;### For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;
### Summary
The previously reported open redirect ([GHSA-6qq8-5wq3-86rp](https://github.com/traefik/traefik/security/advisories/GHSA-6qq8-5wq3-86rp)) is not fixed correctly. The safePrefix function can be tricked to return an absolute URL.&lt;/p&gt;
&lt;p&gt;### Details
The Traefik API [dashboard component](https://github.com/traefik/traefik/blob/master/pkg/api/dashboard/dashboard.go) tries to validate that the value of the header X-Forwarded-Prefix is a site relative path:
```go
http.Redirect(resp, req, safePrefix(req)+&amp;#34;/dashboard/&amp;#34;, http.StatusFound)
```&lt;/p&gt;
&lt;p&gt;```go
func safePrefix(req *http.Request) string {
	prefix := req.Header.Get(&amp;#34;X-Forwarded-Prefix&amp;#34;)
	if prefix == &amp;#34;&amp;#34; {
		return &amp;#34;&amp;#34;
	}&lt;/p&gt;
&lt;p&gt;parse, err := url.Parse(prefix)
	if err != nil {
		return &amp;#34;&amp;#34;
	}&lt;/p&gt;
&lt;p&gt;return parse.Path
}
```&lt;/p&gt;
&lt;p&gt;### PoC
An attacker can bypass this by sending the following payload:&lt;/p&gt;
&lt;p&gt;```bash
curl -v &amp;#39;http://traefik.localhost&amp;#39; -H &amp;#39;X-Forwarded-Prefix: %0d//a.com&amp;#39;
[...]
&amp;gt; HTTP/1.1 302 Found
&amp;gt; Location: //a.com/dashboard/
```&lt;/p&gt;
&lt;p&gt;or sim…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-h924-8g65-j9wg</guid>
    </item>
    <item>
      <title>openSUSE-SU-2024:14567-1 — govulncheck-vulndb-0.0.20241209T183251-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2024:14567-1</link>
      <description>&lt;p&gt;govulncheck-vulndb-0.0.20241209T183251-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;govulncheck-vulndb-0.0.20241209T183251-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2024:14567-1</guid>
    </item>
  </channel>
</rss>
