A AegiFlow
HIGHCVSS 7.0EPSS 0.4%

CVE-2026-88008

CVE-2026-88008 updated by NVD

Published
2026-09-10
Modified
2026-09-16
EPSS percentile
29%
Sources
github-advisory, nvd

Summary

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.

Affected packages

EcosystemPackageAffected versionsFixed versions
Gogithub.com/traefik/traefik/v22.11.57
Gogithub.com/traefik/traefik/v33.7.13

Remediation: Upgrade to 2.11.57 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.