---
id: CVE-2021-32813
aliases:
  - GHSA-m697-4v8f-55qg
  - GO-2022-0923
title: Header dropping in traefik
summary: Header dropping in traefik
severity: medium
cvss: 4.8
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'
vendor: traefik
product: github.com/traefik/traefik/v2
ecosystem: go
affected:
  - github.com/traefik/traefik/v2 < 2.4.13
  - github.com/traefik/traefik <= 1.7.30
patched:
  - github.com/traefik/traefik/v2 2.4.13
published: '2021-08-05'
updated: '2026-07-08'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-m697-4v8f-55qg'
references:
  - url: 'https://github.com/traefik/traefik/security/advisories/GHSA-m697-4v8f-55qg'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2021-32813'
  - url: >-
      https://github.com/traefik/traefik/pull/8319/commits/cbaf86a93014a969b8accf39301932c17d0d73f9
  - url: 'https://github.com/traefik/traefik/releases/tag/v2.4.13'
  - url: github.com/traefik/traefik
tags:
  - osv
  - go
epss: 0.011
epssPercentile: 0.64242
ingestedAt: '2026-07-09T18:56:36.611Z'
---

## Overview

# Impact

There exists a potential header vulnerability in Traefik's handling of the Connection header. Active exploitation of this issue is unlikely, as it requires that a removed header would lead to a privilege escalation, however, the Traefik team has addressed this issue to prevent any potential abuse.

# Details

If you have a chain of Traefik middlewares, and one of them sets a request header `Important-Security-Header`, then sending a request with the following Connection header will cause it to be removed before the request was sent:

```
curl 'https://example.com' -H "Connection: Important-Security-Header" -0
```

In this case, the backend does not see the request header `Important-Security-Header`.

# Patches

Traefik v2.4.x: https://github.com/traefik/traefik/releases/tag/v2.4.13

# Workarounds

No.

# For more information

If you have any questions or comments about this advisory, [open an issue](https://github.com/traefik/traefik/issues).


## Affected packages

- `github.com/traefik/traefik/v2 < 2.4.13`
- `github.com/traefik/traefik <= 1.7.30`

## Remediation

Upgrade to a patched release:

- `github.com/traefik/traefik/v2 2.4.13`
