Skip to main content

V2: Traefik: ForwardAuth identity spoofing via dot-form header alias (CVE-2026-88011)

0
Medium
Published: 09/10/2026 (09/10/2026, 20:28:15 UTC)
Source: GCVE Database
Product: github.com/traefik/traefik/v2

Description

Traefik contains a medium severity vulnerability (CVE-2026-88011) involving header aliasing that allows identity spoofing via dot-form header names. Traefik treats headers with dashes, underscores, and dots as distinct, but some backends collapse these into the same variable, enabling an attacker to bypass ForwardAuth identity assertions. This affects Traefik v1.x, v2 up to 2.11.55, and v3 from 3.0.0 to 3.7.11. The vulnerability allows a permitted lower-privilege client to impersonate another user or role. Patches are available in v2.11.56 and v3.7.12, which introduce the aliasHeadersStrategy option to mitigate the issue.

CVSS v4.0

Attack Vector
Network
Attack Complexity
Low
Attack Requirements
Present
Privileges Required
Low
User Interaction
None
Vuln. Confidentiality
None
Vuln. Integrity
None
Vuln. Availability
None
Subsq. Confidentiality
High
Subsq. Integrity
High
Subsq. Availability
None
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N

Affected software

Goghsa
github.com/traefik/traefik/v2
Affected versions
<2.11.56
Goghsa
github.com/traefik/traefik/v3
Affected versions
>=3.0.0 <3.7.12

Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/10/2026, 22:05:41 UTC

Technical Analysis

Traefik's handling of HTTP headers allows a client to supply a dot-form alias header (e.g., X.Authenticated.User) that bypasses ForwardAuth middleware's identity replacement. Go's HTTP header canonicalization treats headers with dashes, underscores, and dots as distinct, but backends like PHP collapse these into the same environment variable, causing the client-supplied value to override the authenticated identity. This vulnerability affects Traefik v1.x, all v2 releases before 2.11.56, and v3 releases from 3.0.0 up to 3.7.11. The issue is a sibling to a previous GHSA advisory that blocked underscore aliases but did not address dot aliases. The fix involves setting the new aliasHeadersStrategy option to 'delete' or 'reject' and upgrading to patched versions.

Potential Impact

An attacker permitted by ForwardAuth with a lower-privilege identity can supply a dot-form alias header to impersonate another user or administrative role, potentially compromising confidentiality and integrity of backend applications. The vulnerability was verified with PHP 8.2.27 and 8.2.33 backends. It does not bypass ForwardAuth denial but allows identity spoofing after authentication.

Mitigation Recommendations

A fix is available in Traefik versions 2.11.56 and 3.7.12. Users should upgrade to these versions or later and explicitly set the aliasHeadersStrategy option to 'delete' or 'reject' to prevent header alias spoofing. Unmaintained versions will not receive patches and should be upgraded. This mitigation addresses the issue by removing or rejecting alias headers that could be used for spoofing.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Osv Id
GHSA-rf44-j88r-hh8c
Osv Schema Version
1.4.0
Aliases
["CVE-2026-88011"]
Ecosystems
["Go"]
Database Specific Severity
MODERATE
Cvss Version
4.0

Threat ID: 6aa3295d91cc7f3848d18c0e

Added to database: 09/10/2026, 22:04:13 UTC

Last enriched: 09/10/2026, 22:05:41 UTC

Last updated: 09/10/2026, 22:05:41 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses