Interpretation Conflict in Traefik - CVE-2026-88004

 

Interpretation Conflict in Traefik - CVE-2026-88004

Published: October 7, 2026


Vulnerability identifier: #VU153903
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-88004
CWE-ID: CWE-436
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass backend authorization and compromise the confidentiality and integrity of backend data.

n

The vulnerability exists due to missing sanitization of request trailer names in Traefik's entrypoint header filtering and custom reverse proxy when handling HTTP/1.1 chunked request trailers or HTTP/2 request trailers. A remote attacker can send a specially crafted request containing aliasing or trusted header names in trailers to bypass backend authorization and compromise the confidentiality and integrity of backend data.

n

Downstream exploitation requires a backend that merges trailers into its header namespace or consumes trailer fields in security decisions. Delivery of attacker-chosen trailer values additionally requires middleware that reads the request body before proxy cloning, such as the retry middleware configured with status codes or the buffering middleware. Without prior body buffering, forwarding is limited to trailer names without values.


Affected software

Traefik

How to mitigate CVE-2026-88004

Install security update from vendor's website.

Traefik - update to 3.7.13

External References

Related Security Bulletins