THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-x677-9fxg-v5c5 (high) — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

[GHSA] GHSA-x677-9fxg-v5c5 (high) — Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

highgithub_advisoriesPublished 2026-08-06

GHSA-x677-9fxg-v5c5 Severity: high CVE: CVE-2026-54763

Traefik: Incomplete fix for CVE-2026-33433 + CVE-2026-39858 cross-cohort: headerField underscore-variant identity spoofing in BasicAuth / DigestAuth / ForwardAuth

## Summary

There is a high severity vulnerability in Traefik's BasicAuth, DigestAuth, and ForwardAuth middlewares. The fix for CVE-2026-33433 stripped canonical-cased spoofed iden

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-x677-9fxg-v5c5