SB20261007231 - Multiple vulnerabilities in Traefik



SB20261007231 - Multiple vulnerabilities in Traefik

Published: October 7, 2026

Security Bulletin ID SB20261007231
CSH Severity
High
Patch available
YES
Number of vulnerabilities 5
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 60% Medium 20% Low 20%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 5 vulnerabilities.


1) Interpretation Conflict (CVE-ID: CVE-2026-88004)

CWE-ID: CWE-436 - Interpretation Conflict

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass backend authorization and compromise the confidentiality and integrity of backend data.

n

The vulnerability exists due to missing sanitization of request trailer names in Traefik's entrypoint header filtering and custom reverse proxy when handling HTTP/1.1 chunked request trailers or HTTP/2 request trailers. A remote attacker can send a specially crafted request containing aliasing or trusted header names in trailers to bypass backend authorization and compromise the confidentiality and integrity of backend data.

n

Downstream exploitation requires a backend that merges trailers into its header namespace or consumes trailer fields in security decisions. Delivery of attacker-chosen trailer values additionally requires middleware that reads the request body before proxy cloning, such as the retry middleware configured with status codes or the buffering middleware. Without prior body buffering, forwarding is limited to trailer names without values.


2) Improper Authentication (CVE-ID: CVE-2026-88007)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to read victim-only data and perform unauthorized actions as the victim.

The vulnerability exists due to improper authentication caused by missing connection-scoped backend transport initialization in the HTTP/3 entrypoint's ConnContext when forwarding HTTP/3 requests to backends using connection-bound NTLM or Negotiate authentication. A remote attacker can send requests through a separate HTTP/3 client that reuses a victim-authenticated backend connection without presenting the victim's credentials to read victim-only data and perform unauthorized actions as the victim.

Exploitation requires HTTP/3 enabled on the entrypoint, backend keep-alive and connection reuse, and access to the same route as the victim. Deployments using ordinary per-request authentication are not affected.


3) Information Exposure Through Timing Discrepancy (CVE-ID: CVE-2026-88010)

CWE-ID: CWE-208 - Information Exposure Through Timing Discrepancy

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to enumerate configured usernames.

The vulnerability exists due to an observable timing discrepancy in the BasicAuth middleware's checkPassword function when coalescing concurrent credential checks using a key that depends on the stored secret. A remote attacker can send overlapping requests with the same password and different usernames and compare their response times to enumerate configured usernames.

The overlapping requests must reach the same Traefik process. Credential disclosure and authentication bypass are not possible.


4) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-88009)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information, bypass routing and path-scoped authorization controls, and evade access logging.

The vulnerability exists due to inconsistent interpretation of HTTP request-targets in Traefik's HTTP routing and reverse-proxy components when processing rootless or opaque HTTP/1.x request-targets. A remote attacker can send a specially crafted request whose target is evaluated as "/" but forwarded using its opaque value to disclose sensitive information, bypass routing and path-scoped authorization controls, and evade access logging.

Exploitation requires a backend that interprets the forwarded target as a protected path or virtual host. The issue can occur with stock entrypoint defaults.


5) Inconsistent interpretation of HTTP requests (CVE-ID: CVE-2026-88008)

CWE-ID: CWE-444 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')

CVSSv4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to access protected backend endpoints and perform operations without the required security checks.

The vulnerability exists due to unrestricted protocol upgrades that enable HTTP request smuggling in Traefik's default HTTP reverse proxy when handling client-initiated HTTP/1.1 protocol upgrades. A remote attacker can send an h2c upgrade request through an unprotected router and transmit HTTP/2 requests over the resulting raw byte tunnel, bypassing routing and security middleware, to access protected backend endpoints and perform operations without the required security checks.

Exploitation requires an unprotected router and a protected router pointing to the same backend. The backend must accept the h2c upgrade without validating the Connection header listing and return 101 Switching Protocols. Explicitly configured h2c backend support is not required.


Remediation

Install update from vendor's website.