Identity Spoofing Vulnerability in Traefik HTTP Reverse Proxy and Load Balancer
CVE-2026-88011
5.3MEDIUM
What is CVE-2026-88011?
Traefik, an open-source HTTP reverse proxy and load balancer, is impacted by a vulnerability that allows a client-supplied dot-form header to persist through ForwardAuth replacements, creating a potential for identity spoofing. This arises because the application does not adequately normalize headers. Hence, backend systems could inadvertently use client values rather than those asserted by Traefik. To mitigate this, users must enable the aliasHeadersStrategy protection, which is disabled by default. Patches are available in versions 2.11.56 and 3.7.12.
Affected Version(s)
traefik < 2.11.56 < 2.11.56
traefik >= 3.0.0, < 3.7.12 < 3.0.0, 3.7.12
