PatchSiren cyber security CVE debrief
CVE-2026-88009 traefik CVE debrief
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability that allows for cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. This issue arises from Traefik's handling of rootless HTTP/1 request targets, which can lead to security risks when the backend interprets the opaque target as a path. The vulnerability is fixed in Traefik versions 2.11.57 and 3.7.13.
- Vendor
- traefik
- Product
- Unknown
- CVSS
- HIGH 8.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-10
- Original CVE updated
- 2026-09-14
- Advisory published
- 2026-09-10
- Advisory updated
- 2026-09-14
Who should care
Defenders responsible for Traefik configurations and deployments should assess exposure and prioritize patching or upgrading to fixed versions. They should also review their current Traefik configurations and monitor for any suspicious activity.
Why it matters
The CVE-2026-88009 vulnerability in Traefik allows for cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. Defenders should prioritize patching or upgrading to fixed versions, review current configurations, and monitor for suspicious activity.
- Cross-vhost routing bypass, allowing unauthorized access to sensitive resources
- Path-scoped authorization bypass, potentially leading to unauthorized actions
- Access-log evasion, making it difficult to detect and respond to security incidents
Technical summary
Traefik, an open-source HTTP reverse proxy and load balancer, has a vulnerability that allows for cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. This issue arises from Traefik's handling of rootless HTTP/1 request targets, which can lead to security risks when the backend interprets the opaque target as a path. The vulnerability is caused by Traefik's handling of rootless HTTP/1 request targets, which can lead to cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. The issue is fixed in Traefik versions 2.11.57 and 3.7.13. Defenders should prioritize patching or upgrading to fixed versions of Traefik, specifically 2.11.57 or 3.7.13, to The
Defensive priority
Defenders should prioritize patching or upgrading to fixed versions of Traefik, specifically 2.11.57 or 3.7.13, to mitigate the vulnerability. They should also review their current Traefik configurations and monitor for any suspicious activity.
Recommended defensive actions
- Patch or upgrade to Traefik version 2.11.57 or 3.7.13
- Review current Traefik configurations
- Monitor for suspicious activity
- Confirm whether affected Traefik deployments exist in managed environments and assign an owner for follow-up
- Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability is caused by Traefik's handling of rootless HTTP/1 request targets, which can lead to cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion. The issue is fixed in Traefik versions 2.11.57 and 3.7.13.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-88009 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-88009
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-88009 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88009
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/traefik/traefik/commit/58d1e9ca204526823211e30fd4634101c59d58e9
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/traefik/traefik/pull/13796
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/traefik/traefik/releases/tag/v2.11.57
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/traefik/traefik/releases/tag/v3.7.13
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/traefik/traefik/security/advisories/GHSA-f52w-8j3h-j724
[email protected] - Patch, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.