
🚨High - Traefik BasicAuth/DigestAuth Identity Spoof via headerField Canonicalization (CVE-2026-33433) Traefik BasicAuth/DigestAuth can be bypassed when headerField is set to a non-canonical HTTP header name: an authenticated attacker injects the canonical header variant and the backend reads it first, overriding Traefik’s non-canonical write to impersonate another identity. Default/canonical headerField configs aren’t affected. 👉Affected: Traefik < 2.11.42, 3.6.x < 3.6.11, 3.7.0-ea < 3.7.0-ea.3 | Upgrade to 2.11.42 / 3.6.11 / 3.7.0-ea.3
Post summary
CVE‑2026‑33433 enables identity spoofing in Traefik BasicAuth/DigestAuth via non‑canonical headerField; upgrading to the listed patch versions mitigates the issue.
