Improper Authentication in Traefik - CVE-2026-88007
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to read victim-only data and perform unauthorized actions as the victim.
The vulnerability exists due to improper authentication caused by missing connection-scoped backend transport initialization in the HTTP/3 entrypoint's ConnContext when forwarding HTTP/3 requests to backends using connection-bound NTLM or Negotiate authentication. A remote attacker can send requests through a separate HTTP/3 client that reuses a victim-authenticated backend connection without presenting the victim's credentials to read victim-only data and perform unauthorized actions as the victim.
Exploitation requires HTTP/3 enabled on the entrypoint, backend keep-alive and connection reuse, and access to the same route as the victim. Deployments using ordinary per-request authentication are not affected.