Identity Spoofing Vulnerability in Traefik HTTP Proxy by Traefik Labs
CVE-2026-88879

5.3MEDIUM

Key Information:

Vendor

Traefik

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88879?

An identity spoofing vulnerability exists in Traefik due to improper canonicalization of header names. Affected versions struggle to distinguish between headers that use dashes and periods, effectively treating similar headers as distinct. This flaw allows an attacker to smuggle a header alias that can trick various backends into misinterpreting identity information, granting unauthorized access or privileges. Fixes are included in Traefik v2.11.56 and v3.7.12, but users must update their configurations to utilize the 'delete' or 'reject' strategies for the alias headers to mitigate the issue.

Affected Version(s)

traefik 0 < 2.11.56

traefik 3.0.0 <= 3.7.13

traefik 2.11.56

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

velgusgus599
.