← All CVEs NewScan detects
medium

CVE-2026-88879

Traefik canonicalizes header names on dashes only, so X-Auth-User, X_Auth_User and X.Auth.User are three headers to Traefik and ONE variable to a CGI/WSGI/PHP/NGINX backend - a client smuggles a dot-form alias past the middleware that manages the canonical header and the backend reads the attacker's value as the asserted identity (CVSS 5.3)

Severity
medium
Affected product
Traefik
Affected versions
Traefik ≥ 2.0.0, < 2.11.56
Affected versions
Traefik ≥ 3.0.0, < 3.7.12
Fixed in
Traefik 2.11.56
Fixed in
Traefik 3.7.12
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-cwr6-3wm2-9xhw, advisory API v2 range `< 2.11.56`, v3 `>= 3.0.0, < 3.7.12`. The prose also names v1.x as affected, but this arm still starts at ge 2.0.0: v1 is EOL with no fixed release, so a row claiming it would hand an operator a `fixed_in` that does not exist on their branch. An INCOMPLETE FIX for GHSA-x677-9fxg-v5c5, which blocked only the underscore form. Read the remediation carefully before reporting it as closed by an upgrade alone: 2.11.56/3.7.12 only ADD the aliasHeadersStrategy entry-point option and it defaults to 'keep', so an upgraded-but-unconfigured install is still exposed - which is exactly why the version gate here is the weaker half of the claim and the row stays medium.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-88879 (see the 2.x row, including why an upgrade alone does not close it).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →