A rootless HTTP request target can bypass Traefik path authorization and reach protected backend routes.
Traefik authorizes empty parsed path fields while the backend receives the attacker-controlled opaque target.
Traefik, a reverse proxy and Kubernetes ingress controller commonly deployed at application boundaries.
Unauthenticated access to path-protected or alternate-virtual-host backend resources
Traefik leads even though the impact rank placed Samsung second: Traefik’s ingress-to-impact path is reproduced in public code, while Samsung has not disclosed how an image reaches its decoder, whether interaction is required, or which process executes it.
Detail, proof-of-concept code and 4 sources
Go stores the rootless request target in URL.Opaque while leaving the path and authority fields inspected by Traefik empty.
Traefik can consequently approve the request as path / and forward the opaque value to a backend that interprets it as a protected path or another virtual host.
The patch rejects opaque targets at entry and clears URL.Opaque before proxying; fixed releases are available.
- access:network:internet
- reachable from the public internet
- interaction:none
- no user action required
- Reaches end-of-life hardware
- No
The first two fields are unknown because their artifact-acceptance and revocation premises do not apply to this code-path fix.