Traefik 是一个开源的 HTTP 反向代理和负载均衡器。在版本 2.11.0 至 2.11.57 以及 3.7.13 之前,HTTP/3 入口点的 没有调用 ,导致 使用共享的后端传输层,而不是为每个前端连接分配专属的传输层。当启用 HTTP/3、后端使用基于连接的 NTLM 或 Negotiate 身份验证,且启用了后端 Keep-Alive 时,一个无关的客户端可以复用已为受害者认证的后端连接,从而读取仅对受害者可见的数据,并冒充该受害者行事,而无需使用受害者的凭证。此问题已在版本 2.11.57 和 3
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88877 | 9.8 CRITICAL | Traefik v3.7.0 Authentication Bypass via from-to-www-redirect |
| CVE-2026-88009 | 8.8 HIGH | Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing |
| CVE-2026-88004 | 7.0 HIGH | Traefik entrypoint header-name sanitization bypassed via request trailers |
| CVE-2026-88008 | 7.0 HIGH | Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| CVE-2026-88879 | 5.3 MEDIUM | Traefik before v2.11.56 Identity Spoofing via Header Alias |
| CVE-2026-88878 | 5.3 MEDIUM | Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass |
| CVE-2026-88011 | 5.3 MEDIUM | Traefik: ForwardAuth identity spoofing via dot-form header alias |
| CVE-2026-88012 | 5.3 MEDIUM | Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body upload |
No comments yet