Inconsistent interpretation of HTTP requests in Traefik - CVE-2026-88008
Published: October 7, 2026
Vulnerability details
The vulnerability allows a remote attacker to access protected backend endpoints and perform operations without the required security checks.
The vulnerability exists due to unrestricted protocol upgrades that enable HTTP request smuggling in Traefik's default HTTP reverse proxy when handling client-initiated HTTP/1.1 protocol upgrades. A remote attacker can send an h2c upgrade request through an unprotected router and transmit HTTP/2 requests over the resulting raw byte tunnel, bypassing routing and security middleware, to access protected backend endpoints and perform operations without the required security checks.
Exploitation requires an unprotected router and a protected router pointing to the same backend. The backend must accept the h2c upgrade without validating the Connection header listing and return 101 Switching Protocols. Explicitly configured h2c backend support is not required.