CVE-2026-88011
Traefik ForwardAuth identity spoofing via a dot-form header alias - the client supplies X.Authenticated.User alongside the canonical X-Authenticated-User that ForwardAuth writes, and Go's lexical header ordering makes the attacker's value win at the backend (CVSS 5.3)
- Severity
- medium
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.0.0, < 2.11.56
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.12
- Fixed in
- Traefik 2.11.56
- Fixed in
- Traefik 3.7.12
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-rf44-j88r-hh8c is the SAME defect as CVE-2026-88879 (GHSA-cwr6-3wm2-9xhw) with identical ranges, narrated from the ForwardAuth end - the second of today's two duplicate-id Traefik pairs. Kept as its own row for the same reason as the CVE-2026-88012/88878 pair: an assessor keys remediation on the id. Paired both ways via `cves`.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-88011 (see the 2.x row for the duplicate-id rationale).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →