Description
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12.
Published: 2026-09-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Authentication Bypass via Identity Spoofing
Action: Patch
AI Analysis

Impact

Traefik, an open‑source HTTP reverse proxy and load balancer, has a flaw in its ForwardAuth feature that allows a client to supply a dot‑form header such as X.Authenticated.User. Because the Go runtime treats this header as distinct from the expected X-Authenticated-User, the header persists during the ForwardAuth replacement when underscoreHeadersStrategy is used. Downstream backends that collapse dot‑form and hyphenated header names then receive the client‑supplied value instead of the identity that Traefik asserted, permitting an attacker to spoof the authenticated identity for any header handled by Traefik. This reflects authentication bypass and header manipulation weaknesses (CWE‑290 and CWE‑444).

Affected Systems

Traefik versions prior to 2.11.56 and the 3.x line up to 3.7.12 are impacted. Users running 2.11.56 or later, or 3.7.12 or later, benefit from an official fix that removes the vulnerability.

Risk and Exploitability

The vulnerability carries a CVSS base score of 5.3, indicating moderate risk. The EPSS score is below 1%, showing that current exploitation probability is low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker can exploit this flaw from external HTTP traffic by sending a crafted dot‑form header to the Traefik instance, with no additional privileges required.

Generated by OpenCVE AI on September 23, 2026 at 02:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Traefik to version 2.11.56 or later, or to 3.7.12 or later, to apply the official patch.
  • Enable the aliasHeadersStrategy option for ForwardAuth and configure it to delete or reject dot‑form headers, ensuring that such headers are removed before reaching backend services.
  • Configure downstream backends to perform strict header validation or to strip dot‑form headers, reducing the risk of header name collisions.

Generated by OpenCVE AI on September 23, 2026 at 02:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-rf44-j88r-hh8c Traefik: ForwardAuth identity spoofing via dot-form header alias
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-444
References
Metrics threat_severity

None

threat_severity

Critical


Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Fri, 11 Sep 2026 09:30:00 +0000

Type Values Removed Values Added
First Time appeared Traefik
Traefik traefik
Vendors & Products Traefik
Traefik traefik

Thu, 10 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
Description Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12.
Title Traefik: ForwardAuth identity spoofing via dot-form header alias
Weaknesses CWE-290
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T14:42:22.088Z

Reserved: 2026-09-09T19:19:27.407Z

Link: CVE-2026-88011

cve-icon Vulnrichment

Updated: 2026-09-15T14:42:15.765Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T16:18:07.933

Modified: 2026-09-15T15:17:24.163

Link: CVE-2026-88011

cve-icon Redhat

Severity : Critical

Publid Date: 2026-09-10T15:31:55Z

Links: CVE-2026-88011 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:30:17Z

Weaknesses
  • CWE-290

    Authentication Bypass by Spoofing

  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')