CVE-2026-88011High· 8.1▾ TwilightTraefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Exploit-prediction probability, daily snapshots since Sep 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.2%
5.3 → 8.1
medium → high
Last analysed / modified upstream
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12.
traefik < 2.11.56traefik >= 3.0.0, < 3.7.12Upgrade past the affected range:
traefik 3.7.12Affected packages:
github.com/traefik/traefik/v2 < 2.11.56github.com/traefik/traefik/v3 >= 3.0.0, < 3.7.12Patched in:
github.com/traefik/traefik/v2 2.11.56github.com/traefik/traefik/v3 3.7.12Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-88012Medium· 5.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88008Critical· 9.1Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88879High· 8.2Traefik is an HTTP reverse proxy and load balancer
CVE-2026-88009High· 8.2Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88004High· 7.4Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88007Critical· 9.1Traefik is an open source HTTP reverse proxy and load balancer