Skip to content

Topic

HTTP Header Spoofing

Sending forged HTTP headers from a client to impersonate a trusted upstream component or claim privileges at a proxy or application.

Current clusters

build1 publisher

Spoofed admin headers hit Traefik's catchall 500 times out of 500

Traefik 3.6's release material says child routers cannot be called directly. A test on 3.6.25 sent the exact header a child router matches, on a path outside the parent prefix, 500 times, and none of it reached the admin service.

Publishers:dev.to

Reality

Evidence62
Adoption
Insufficient
Hype gap+12
Incentives22
Confidence58