Impact
Traefik, an open‑source HTTP reverse proxy and load balancer, has a flaw in its ForwardAuth feature that allows a client to supply a dot‑form header such as X.Authenticated.User. Because the Go runtime treats this header as distinct from the expected X-Authenticated-User, the header persists during the ForwardAuth replacement when underscoreHeadersStrategy is used. Downstream backends that collapse dot‑form and hyphenated header names then receive the client‑supplied value instead of the identity that Traefik asserted, permitting an attacker to spoof the authenticated identity for any header handled by Traefik. This reflects authentication bypass and header manipulation weaknesses (CWE‑290 and CWE‑444).
Affected Systems
Traefik versions prior to 2.11.56 and the 3.x line up to 3.7.12 are impacted. Users running 2.11.56 or later, or 3.7.12 or later, benefit from an official fix that removes the vulnerability.
Risk and Exploitability
The vulnerability carries a CVSS base score of 5.3, indicating moderate risk. The EPSS score is below 1%, showing that current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit this flaw from external HTTP traffic by sending a crafted dot‑form header to the Traefik instance, with no additional privileges required.
OpenCVE Enrichment
Github GHSA