THREAT OPS › Threat News › [GHSA] GHSA-x677-9fxg-v5c5 (high) — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
[GHSA] GHSA-x677-9fxg-v5c5 (high) — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
GHSA-x677-9fxg-v5c5 Severity: high CVE: CVE-2026-54763
Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth
## Summary
There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed iden
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- eec68dce064f843b4317c4393aaea81b6dea31d6sha1
- CVE-2026-33433cve
- CVE-2026-39858cve
- CVE-2026-54763cve
- CVE-2026-29054cve
- CVE-2026-35051cve
- http://echo:8888url
- https://nginx.org/en/docs/http/ngx_http_core_module.html#underscores_in_headers):url
Original source: https://github.com/advisories/GHSA-x677-9fxg-v5c5