chiprook
← Security
SecurityOctober 4, 2026, 05:40

Traefik ForwardAuth identity spoofing via dot-form header aliases patched

CVE-2026-88879 in Traefik before v2.11.56 and v3.7.12 lets attackers spoof identity headers: backends on PHP, CGI and WSGI fold X-Auth-User, X_Auth_User and X.Auth.User into one variable, so an attacker-supplied alias can win. The fix requires explicitly setting aliasHeadersStrategy to delete or reject.

Traefik ForwardAuth identity spoofing via dot-form header aliases patched
#Traefik
Read next
Security

CVE-2026-84428: Schema Validation Bypass in Fastify Header Normalization

Security

Apache Tomcat 11.0.26 fixes HTTP/2 header mix-up regression CVE-2026-86350

Security

CVE-2026-48710 (BadHost): malformed Host header bypasses Starlette path authorization

Security

Cybersecurity Roundup: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats