Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-rf44-j88r-hh8c | Traefik: ForwardAuth identity spoofing via dot-form header alias |
Thu, 10 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12. | |
| Title | Traefik: ForwardAuth identity spoofing via dot-form header alias | |
| Weaknesses | CWE-290 | |
| References |
|
|
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-10T15:31:55.215Z
Reserved: 2026-09-09T19:19:27.407Z
Link: CVE-2026-88011
No data.
Status : Awaiting Analysis
Published: 2026-09-10T16:18:07.933
Modified: 2026-09-10T19:54:25.810
Link: CVE-2026-88011
No data.
OpenCVE Enrichment
Updated: 2026-09-10T17:30:10Z
Github GHSA