Traefik 是一个 HTTP 反向代理和负载均衡器。在 v3.7.0 到 v3.7.11 版本中,Kubernetes ingress-nginx 提供者对同时带有认证注解和 注解的 Ingress 资源处理不当。对于这类 Ingress,该提供者会创建一个额外的“兄弟”路由器,该路由器仅根据主机名进行匹配,仅携带 中间件,并且仍然指向父路由器的受保护后端服务。 由于 并非终止型处理器(terminal handler),当请求的 URL 不匹配其重定向模式时,请求会被转发至后端服务。同时,因为该重定向模式仅接
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88007 | 9.1 CRITICAL | Traefik HTTP/3 Backend NTLM Connection Reuse |
| CVE-2026-88009 | 8.8 HIGH | Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing |
| CVE-2026-88004 | 7.0 HIGH | Traefik entrypoint header-name sanitization bypassed via request trailers |
| CVE-2026-88008 | 7.0 HIGH | Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| CVE-2026-88879 | 5.3 MEDIUM | Traefik before v2.11.56 Identity Spoofing via Header Alias |
| CVE-2026-88878 | 5.3 MEDIUM | Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass |
| CVE-2026-88011 | 5.3 MEDIUM | Traefik: ForwardAuth identity spoofing via dot-form header alias |
| CVE-2026-88012 | 5.3 MEDIUM | Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body upload |
No comments yet