CVE-2026-54763: Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
There is a high severity vulnerability in Traefik’s BasicAuth, DigestAuth, and ForwardAuth
middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed identity headers
(e.g. X-Auth-User) before writing Traefik’s own value, but did not account for
underscore-variant header names (e.g. X_Auth_User), which many backends normalize
identically to the dashed form. An attacker able to reach a protected route could inject
an underscore-variant header that survives Traefik’s stripping and reaches the backend
alongside — or, on the unauthenticated ForwardAuth authResponseHeaders path, instead of
— the value Traefik intended to set, spoofing identity or authorization context. This is
fixed by setting the new allowHeadersWithUnderscores: false entry point option, which
strips all headers with underscores in their names before routing.
The fix for CVE-2026-33433 (GHSA-qr99-7898-vr7c, “BasicAuth/DigestAuth Identity Spoofing via Non-Canonical headerField”, patched in v2.11.42 / v3.6.12 / v3.7.0-ea.3) added req.Header.Del(headerField) before the literal-key writeback in pkg/middlewares/auth/basic_auth.go and pkg/middlewares/auth/digest_auth.go. Go’s Header.Del calls textproto.CanonicalMIMEHeaderKey which canonicalizes ASCII CASE and treats - as a word separator — so the fix correctly strips canonical-cased attacker headers (X-Auth-User, x-auth-user, X-AUTH-USER, etc.).
However, textproto.CanonicalMIMEHeaderKey does NOT treat _ as a separator. Attacker-supplied underscore-variant headers such as X_Auth_User survive Header.Del("X-Auth-User") intact and are forwarded to the backend alongside Traefik’s own writeback. Many common backends (CGI/WSGI per RFC 3875, PHP $_SERVER, nginx with underscores_in_headers on, Tomcat / Java EE servlet containers, ASGI/WSGI frameworks) normalize _ ↔ - equivalently or expose both forms to application code that may read the attacker’s value.
This is the direct cross-cohort sibling of the threat model the maintainer accepted in CVE-2026-39858 (GHSA-5m6w-wvh7-57vm, “Forwarded alias spoofing pre-auth decision bypass”), which fixed the underscore-variant of the X-Forwarded-* family via isManagedXHeader in pkg/middlewares/forwardedheaders/forwarded_header.go. The CVE-2026-39858 advisory body states verbatim:
“When the backend normalizes underscore and dash header forms equivalently, an attacker can inject spoofed trust context — such as a trusted scheme or host — through the alias headers and bypass authentication on protected routes without valid credentials.”
The same threat model applies to the operator-configurable headerField (BasicAuth, DigestAuth) and authResponseHeaders (ForwardAuth, ingress-nginx snippet provider), but the underscore-handling primitive (isManagedXHeader) was not extended to those middlewares. I verified the bypass end-to-end on traefik:v3.6.14 (the latest patched release containing both fixes) using a default-recommended canonical headerField: "X-Auth-User" config and reproduced the bypass with a single curl -H "X_Auth_User: superadmin" ... request alongside valid BasicAuth credentials.
The defect is present in four code paths at HEAD eec68dce064f843b4317c4393aaea81b6dea31d6:
pkg/middlewares/auth/basic_auth.go:101-105— BasicAuthheaderFieldpkg/middlewares/auth/digest_auth.go:99-103— DigestAuthheaderFieldpkg/middlewares/auth/forward.go:304-310— ForwardAuthauthResponseHeadersper-name writebackpkg/middlewares/ingressnginx/snippet/snippet.go:480-486— Ingress-NGINX snippetauthResponseHeadersper-name writeback
The ForwardAuth instance (#3) is particularly notable: the attacker does NOT need credentials. The authResponseHeaders mechanism is intended to copy identity headers from the trusted auth server only; the underscore-variant bypass lets an unauthenticated attacker pre-inject the same identity header before any auth happens.
The fast proxy at pkg/proxy/fast/proxy.go:139 explicitly calls DisableNormalizing() on the outgoing fasthttp request, guaranteeing that the underscore-variant header reaches the backend wire verbatim. The standard httputil.ReverseProxy path at pkg/proxy/httputil/proxy.go:55 likewise copies req.Header keys as-is during the wire write.
References
- github.com/advisories/GHSA-x677-9fxg-v5c5
- github.com/traefik/traefik/commit/108a5264473a2cbc8f12d6d691a3c6553cdf2c1b
- github.com/traefik/traefik/pull/13262
- github.com/traefik/traefik/releases/tag/v2.11.51
- github.com/traefik/traefik/releases/tag/v3.6.22
- github.com/traefik/traefik/releases/tag/v3.7.6
- github.com/traefik/traefik/security/advisories/GHSA-x677-9fxg-v5c5
- nvd.nist.gov/vuln/detail/CVE-2026-54763
Code Behaviors & Features
Detect and mitigate CVE-2026-54763 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →