{"id":"GHSA-rf44-j88r-hh8c","summary":"Traefik: ForwardAuth identity spoofing via dot-form header alias","details":"## Summary\n\nThere is a medium severity vulnerability in Traefik's handling of request headers whose name aliases another header name. Go canonicalizes header names on dashes only, so `X-Auth-User`, `X_Auth_User` and `X.Auth.User` are three distinct headers to Traefik, while backends that derive variable names from header names (CGI, WSGI, PHP, NGINX, and others) collapse all of them into the same variable. A client can therefore smuggle an alias of a header that Traefik manages past the middleware managing it — for example a dot-form `X.Authenticated.User` alongside the canonical `X-Authenticated-User` written by the ForwardAuth middleware — and have such a backend read the client-supplied value instead of the identity Traefik asserted. Any header Traefik sets is exposed, not only ForwardAuth's. This is an incomplete-fix sibling of GHSA-x677-9fxg-v5c5, which blocked only the underscore form.\n\nThe mitigation is the new `aliasHeadersStrategy` entry point option. It defaults to `keep`, which preserves the previous behavior for backwards compatibility, so it must be explicitly set to `delete` or `reject` to take effect.\n\nTraefik v1.x, the v2 releases up to v2.11.55 and the v3 releases from v3.0.0 to v3.7.11 are affected. The unmaintained lines among them will not receive a patch of their own, and the remedy for their users is to upgrade to v2.11.56 or v3.7.12 and set `aliasHeadersStrategy`.\n\n## Patches\n\n- https://github.com/traefik/traefik/releases/tag/v2.11.56\n- https://github.com/traefik/traefik/releases/tag/v3.7.12\n\n## For more information\n\nIf you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).\n\n\u003cdetails\u003e\n\u003csummary\u003eOriginal Description\u003c/summary\u003e\n\n### Summary\nTraefik's ForwardAuth middleware removes the configured canonical identity header before copying the value returned by the auth service. However, a client-supplied dot-form alias such as `X.Authenticated.User` survives both this replacement and `underscoreHeadersStrategy: delete`.\n\nThe tested PHP 8.2 built-in SAPI maps `X-Authenticated-User` and `X.Authenticated.User` to the same `HTTP_X_AUTHENTICATED_USER` server variable. In Traefik's tested HTTP/1 backend path, the client value is serialized last and overrides the identity asserted by ForwardAuth.\n\nA client whom ForwardAuth permits as a lower-privilege identity can therefore be treated by the backend as another user or role.\n\n### Details\nAt `v3.7.10`, `pkg/server/server_entrypoint_tcp.go:800-818` removes or rejects only names containing `_`. After successful authentication, `pkg/middlewares/auth/forward.go:314-326` deletes and replaces only the canonical `authResponseHeaders` key. The dot alias remains in `req.Header` and the standard reverse proxy forwards both legal field names.\n\nGo's HTTP/1 writer sorts header names lexically, placing `X-Authenticated-User` before `X.Authenticated.User`. PHP then collapses both into one `$_SERVER` key, so the attacker value deterministically wins.\n\nThis is an incomplete-fix sibling of `GHSA-x677-9fxg-v5c5`: the published underscore input is blocked by the new entry-point strategy, while the dot input bypasses that mitigation on the current stable release.\n\n### PoC\n[traefik-dot-forwardauth-poc.zip](https://github.com/user-attachments/files/30898195/traefik-dot-forwardauth-poc.zip)\n\nrun:\n```bash\ndocker compose up -d\nbash verify.sh\ndocker compose down\n```\n\nThe decisive request is:\n\n```http\nGET /probe HTTP/1.1\nHost: 127.0.0.1:18080\nX.Authenticated.User: admin\nConnection: close\n```\n\nExpected backend identity: `lab-user`, as returned by ForwardAuth.\n\nObserved on `v3.7.10`: `admin`.\n\nThe script also verifies that requests without the alias, with the canonical header, and with the already-fixed underscore alias all produce `lab-user`.\n\n### Impact\nApplications that authorize requests using a ForwardAuth-provided identity header can receive an attacker-selected username or role instead. This was runtime-verified with PHP 8.2.27 and 8.2.33; impact on other normalization-prone backends is conditional. A lower-privilege permitted client may consequently impersonate another user or administrative role, affecting confidentiality and integrity.\n\nThis report does not claim bypass of a ForwardAuth denial: the auth service must first permit the request.\n\n\n\u003c/details\u003e\n---","aliases":["CVE-2026-88011","CVE-2026-88879","GO-2026-6455"],"modified":"2026-09-17T17:40:34.771461848Z","published":"2026-09-10T20:28:15Z","database_specific":{"github_reviewed_at":"2026-09-10T20:28:15Z","nvd_published_at":"2026-09-10T16:18:07Z","cwe_ids":["CWE-290"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/traefik/traefik/security/advisories/GHSA-rf44-j88r-hh8c"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-88011"},{"type":"WEB","url":"https://github.com/traefik/traefik/pull/13720"},{"type":"WEB","url":"https://github.com/traefik/traefik/commit/0331801c72329e0eaeb850e53ccce87c57fbecf8"},{"type":"PACKAGE","url":"https://github.com/traefik/traefik"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v2.11.56"},{"type":"WEB","url":"https://github.com/traefik/traefik/releases/tag/v3.7.12"}],"affected":[{"package":{"name":"github.com/traefik/traefik/v2","ecosystem":"Go","purl":"pkg:golang/github.com/traefik/traefik/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"2.11.56"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rf44-j88r-hh8c/GHSA-rf44-j88r-hh8c.json"}},{"package":{"name":"github.com/traefik/traefik/v3","ecosystem":"Go","purl":"pkg:golang/github.com/traefik/traefik/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"3.0.0"},{"fixed":"3.7.12"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-rf44-j88r-hh8c/GHSA-rf44-j88r-hh8c.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N"}]}