Inconsistent interpretation of HTTP requests in Traefik - CVE-2026-88008

 

Inconsistent interpretation of HTTP requests in Traefik - CVE-2026-88008

Published: October 7, 2026


Vulnerability identifier: #VU153907
CSH Severity: High
CVSS v4: 9.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-88008
CWE-ID: CWE-444
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to access protected backend endpoints and perform operations without the required security checks.

The vulnerability exists due to unrestricted protocol upgrades that enable HTTP request smuggling in Traefik's default HTTP reverse proxy when handling client-initiated HTTP/1.1 protocol upgrades. A remote attacker can send an h2c upgrade request through an unprotected router and transmit HTTP/2 requests over the resulting raw byte tunnel, bypassing routing and security middleware, to access protected backend endpoints and perform operations without the required security checks.

Exploitation requires an unprotected router and a protected router pointing to the same backend. The backend must accept the h2c upgrade without validating the Connection header listing and return 101 Switching Protocols. Explicitly configured h2c backend support is not required.


Affected software

Traefik

How to mitigate CVE-2026-88008

Install security update from vendor's website.

Traefik - addressed in versions 2.11.57, 3.7.13

External References

Related Security Bulletins