Interpretation Conflict in Traefik - CVE-2026-88004
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass backend authorization and compromise the confidentiality and integrity of backend data.
nThe vulnerability exists due to missing sanitization of request trailer names in Traefik's entrypoint header filtering and custom reverse proxy when handling HTTP/1.1 chunked request trailers or HTTP/2 request trailers. A remote attacker can send a specially crafted request containing aliasing or trusted header names in trailers to bypass backend authorization and compromise the confidentiality and integrity of backend data.
nDownstream exploitation requires a backend that merges trailers into its header namespace or consumes trailer fields in security decisions. Delivery of attacker-chosen trailer values additionally requires middleware that reads the request body before proxy cloning, such as the retry middleware configured with status codes or the buffering middleware. Without prior body buffering, forwarding is limited to trailer names without values.