V2: Traefik: ForwardAuth identity spoofing via dot-form header alias (CVE-2026-88011)
Traefik contains a medium severity vulnerability (CVE-2026-88011) involving header aliasing that allows identity spoofing via dot-form header names. Traefik treats headers with dashes, underscores, and dots as distinct, but some backends collapse these into the same variable, enabling an attacker to bypass ForwardAuth identity assertions. This affects Traefik v1.x, v2 up to 2.11.55, and v3 from 3.0.0 to 3.7.11. The vulnerability allows a permitted lower-privilege client to impersonate another user or role. Patches are available in v2.11.56 and v3.7.12, which introduce the aliasHeadersStrategy option to mitigate the issue.
AI Analysis
Technical Summary
Traefik's handling of HTTP headers allows a client to supply a dot-form alias header (e.g., X.Authenticated.User) that bypasses ForwardAuth middleware's identity replacement. Go's HTTP header canonicalization treats headers with dashes, underscores, and dots as distinct, but backends like PHP collapse these into the same environment variable, causing the client-supplied value to override the authenticated identity. This vulnerability affects Traefik v1.x, all v2 releases before 2.11.56, and v3 releases from 3.0.0 up to 3.7.11. The issue is a sibling to a previous GHSA advisory that blocked underscore aliases but did not address dot aliases. The fix involves setting the new aliasHeadersStrategy option to 'delete' or 'reject' and upgrading to patched versions.
Potential Impact
An attacker permitted by ForwardAuth with a lower-privilege identity can supply a dot-form alias header to impersonate another user or administrative role, potentially compromising confidentiality and integrity of backend applications. The vulnerability was verified with PHP 8.2.27 and 8.2.33 backends. It does not bypass ForwardAuth denial but allows identity spoofing after authentication.
Mitigation Recommendations
A fix is available in Traefik versions 2.11.56 and 3.7.12. Users should upgrade to these versions or later and explicitly set the aliasHeadersStrategy option to 'delete' or 'reject' to prevent header alias spoofing. Unmaintained versions will not receive patches and should be upgraded. This mitigation addresses the issue by removing or rejecting alias headers that could be used for spoofing.
V2: Traefik: ForwardAuth identity spoofing via dot-form header alias (CVE-2026-88011)
Description
Traefik contains a medium severity vulnerability (CVE-2026-88011) involving header aliasing that allows identity spoofing via dot-form header names. Traefik treats headers with dashes, underscores, and dots as distinct, but some backends collapse these into the same variable, enabling an attacker to bypass ForwardAuth identity assertions. This affects Traefik v1.x, v2 up to 2.11.55, and v3 from 3.0.0 to 3.7.11. The vulnerability allows a permitted lower-privilege client to impersonate another user or role. Patches are available in v2.11.56 and v3.7.12, which introduce the aliasHeadersStrategy option to mitigate the issue.
CVSS v4.0
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Traefik's handling of HTTP headers allows a client to supply a dot-form alias header (e.g., X.Authenticated.User) that bypasses ForwardAuth middleware's identity replacement. Go's HTTP header canonicalization treats headers with dashes, underscores, and dots as distinct, but backends like PHP collapse these into the same environment variable, causing the client-supplied value to override the authenticated identity. This vulnerability affects Traefik v1.x, all v2 releases before 2.11.56, and v3 releases from 3.0.0 up to 3.7.11. The issue is a sibling to a previous GHSA advisory that blocked underscore aliases but did not address dot aliases. The fix involves setting the new aliasHeadersStrategy option to 'delete' or 'reject' and upgrading to patched versions.
Potential Impact
An attacker permitted by ForwardAuth with a lower-privilege identity can supply a dot-form alias header to impersonate another user or administrative role, potentially compromising confidentiality and integrity of backend applications. The vulnerability was verified with PHP 8.2.27 and 8.2.33 backends. It does not bypass ForwardAuth denial but allows identity spoofing after authentication.
Mitigation Recommendations
A fix is available in Traefik versions 2.11.56 and 3.7.12. Users should upgrade to these versions or later and explicitly set the aliasHeadersStrategy option to 'delete' or 'reject' to prevent header alias spoofing. Unmaintained versions will not receive patches and should be upgraded. This mitigation addresses the issue by removing or rejecting alias headers that could be used for spoofing.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-rf44-j88r-hh8c
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-88011"]
- Ecosystems
- ["Go"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 4.0
Threat ID: 6aa3295d91cc7f3848d18c0e
Added to database: 09/10/2026, 22:04:13 UTC
Last enriched: 09/10/2026, 22:05:41 UTC
Last updated: 09/10/2026, 22:05:41 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.