Junglewise Threat Intelligence

CVE-2026-88879: Traefik header name aliasing identity spoofing

CVE-2026-88879 · Severity: high · CVSS 8.2 · Published 2026-09-10

Technologies: Traefik. Vendors: Traefik.

Executive brief

Traefik is an HTTP reverse proxy and load balancer that forwards requests to backend servers and manages authentication headers. A flaw in header name handling allows an attacker to supply an alternative form of a header (e.g., using dots instead of dashes) that bypasses Traefik's authentication middleware but gets normalized by backends, causing the backend to use the attacker's value instead of the legitimate identity Traefik provided. This enables a low-privilege user to impersonate another user or administrator on the backend application.

Technical details

This vulnerability exploits a header name canonicalization mismatch between Traefik and backend systems. Traefik canonicalizes HTTP header names only on dashes (treating X-Auth-User, X_Auth_User, and X.Auth.User as distinct headers), while backends such as PHP, CGI, WSGI, and NGINX collapse all three forms into a single server variable. An authenticated attacker can supply a dot-form alias of a header (e.g., X.Authenticated.User) alongside the canonical header set by ForwardAuth middleware. The dot-form alias bypasses the authentication middleware's header filtering but is normalized by the backend, where lexical header ordering ensures the attacker-supplied value overwrites the legitimate identity. Affected versions include all of v1.x, v2.x up to v2.11.55, and v3.0.0 through v3.7.11. Patches were released in v2.11.56 and v3.7.12, introducing an aliasHeadersStrategy option that defaults to 'keep' for backward compatibility; administrators must explicitly set it to 'delete' or 'reject' for protection.

Affected products

  • Traefik Traefik v1.x, v2.x through v2.11.55, v3.0.0 through v3.7.11

Timeline

  • 2026-09-10: disclosed: CVE-2026-88879 and GHSA-rf44-j88r-hh8c published
  • 2026: patched: v2.11.56 and v3.7.12 released with aliasHeadersStrategy mitigation

References

Related threats