Inconsistent interpretation of HTTP requests in Traefik - CVE-2026-88009
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information, bypass routing and path-scoped authorization controls, and evade access logging.
The vulnerability exists due to inconsistent interpretation of HTTP request-targets in Traefik's HTTP routing and reverse-proxy components when processing rootless or opaque HTTP/1.x request-targets. A remote attacker can send a specially crafted request whose target is evaluated as "/" but forwarded using its opaque value to disclose sensitive information, bypass routing and path-scoped authorization controls, and evade access logging.
Exploitation requires a backend that interprets the forwarded target as a protected path or virtual host. The issue can occur with stock entrypoint defaults.