Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-88011

Опубликовано: 10 сент. 2026
Источник: nvd
CVSS3: 8.1
EPSS Низкий

Описание

Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.56, and from 3.0.0 until 3.7.12, a client-supplied dot-form header such as X.Authenticated.User survives ForwardAuth replacement and underscoreHeadersStrategy because Go treats it as distinct from X-Authenticated-User while normalization-prone CGI, WSGI, PHP, and NGINX backends collapse both names. A backend can consequently consume the client value instead of the identity Traefik asserted, allowing identity spoofing for any header managed by Traefik. The aliasHeadersStrategy protection is disabled by default and must be configured as delete or reject. The mitigation is available in 2.11.56 and 3.7.12.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия до 2.11.56 (исключая)
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Версия от 3.0.0 (включая) до 3.7.12 (исключая)

EPSS

Процентиль: 15%
0.00235
Низкий

8.1 High

CVSS3

Дефекты

CWE-290

Связанные уязвимости

CVSS3: 8.1
debian
8 дней назад

Traefik is an open source HTTP reverse proxy and load balancer. Prior ...

github
8 дней назад

Traefik: ForwardAuth identity spoofing via dot-form header alias

EPSS

Процентиль: 15%
0.00235
Низкий

8.1 High

CVSS3

Дефекты

CWE-290