๐Ÿ” CVE Alert

CVE-2026-88011

UNKNOWN 0.0

Traefik: ForwardAuth identity spoofing via dot-form header alias

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12.

CWE CWE-290
Vendor traefik
Product traefik
Published Sep 10, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for traefik traefik

Be the first to know when new unknown vulnerabilities affecting traefik traefik are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

traefik / traefik
< 2.11.56 >= 3.0.0, < 3.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/traefik/traefik/security/advisories/GHSA-rf44-j88r-hh8c github.com: https://github.com/traefik/traefik/pull/13720 github.com: https://github.com/traefik/traefik/commit/0331801c72329e0eaeb850e53ccce87c57fbecf8 github.com: https://github.com/traefik/traefik/releases/tag/v2.11.56 github.com: https://github.com/traefik/traefik/releases/tag/v3.7.12