Identity Spoofing Vulnerability in Traefik HTTP Proxy by Traefik Labs
CVE-2026-88879
5.3MEDIUM
What is CVE-2026-88879?
An identity spoofing vulnerability exists in Traefik due to improper canonicalization of header names. Affected versions struggle to distinguish between headers that use dashes and periods, effectively treating similar headers as distinct. This flaw allows an attacker to smuggle a header alias that can trick various backends into misinterpreting identity information, granting unauthorized access or privileges. Fixes are included in Traefik v2.11.56 and v3.7.12, but users must update their configurations to utilize the 'delete' or 'reject' strategies for the alias headers to mitigate the issue.
Affected Version(s)
traefik 0 < 2.11.56
traefik 3.0.0 <= 3.7.13
traefik 2.11.56
