CVE-2026-54763 is an authentication and authorization-context spoofing vulnerability in Traefik BasicAuth, DigestAuth, and ForwardAuth middleware. Before versions 2.11.51, 3.6.22, and 3.7.6, the middleware removed spoofed identity headers only when represented in expected canonical dashed forms. Headers using underscore variants were not removed. Backends that normalize underscore and dash characters as equivalent can interpret an attacker-supplied underscore-form header as the trusted identity or authorization header Traefik intended to control. The injected value can reach the backend alongside Traefik's value; on the unauthenticated ForwardAuth authResponseHeaders path, it can be used in place of the intended value.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A previously disclosed Traefik aliasing-header vulnerability referenced as historical context for the configuration controls bypassed by CVE-2026-88004.
A high-severity Traefik authentication-header spoofing vulnerability. Underscore-variant identity headers can survive middleware stripping and be normalized by downstream backends as dashed headers, allowing an attacker who can reach a protected route to spoof identity or authorization context.
A regression/incomplete fix issue in Traefik authentication middleware where underscore-form identity headers such as X_Auth_User can bypass protections, affecting BasicAuth, DigestAuth, and ForwardAuth.
A critical improper authorization vulnerability in Traefik that allows unauthenticated remote attackers to bypass authentication middleware via underscore-variant header injection and spoof identity or authorization context.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.