Identity Spoofing Vulnerability in Traefik HTTP Reverse Proxy and Load Balancer
CVE-2026-88011

5.3MEDIUM

Key Information:

Vendor

Traefik

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88011?

Traefik, an open-source HTTP reverse proxy and load balancer, is impacted by a vulnerability that allows a client-supplied dot-form header to persist through ForwardAuth replacements, creating a potential for identity spoofing. This arises because the application does not adequately normalize headers. Hence, backend systems could inadvertently use client values rather than those asserted by Traefik. To mitigate this, users must enable the aliasHeadersStrategy protection, which is disabled by default. Patches are available in versions 2.11.56 and 3.7.12.

Affected Version(s)

traefik < 2.11.56 < 2.11.56

traefik >= 3.0.0, < 3.7.12 < 3.0.0, 3.7.12

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.