Traefik 是一款 HTTP 反向代理和负载均衡器。在 v2.8.2 至 v2.11.55 以及 v3.0.0 至 v3.7.11 的版本中, 配置项——特别是默认启用且超时时间为 60 秒的 ——未应用于 HTTP/3 请求路径。 是施加于底层 TCP 连接的截止时间(deadline),而该机制无法应用于 QUIC 流;此外,Traefik 的 HTTP/3 服务器在构建时未设置任何超时机制。因此,在启用了 HTTP/3 的入口点上,未认证的远程客户端可以通过缓慢地逐字节发送请求体数据,使请求无限期保持打开
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88877 | 9.8 CRITICAL | Traefik v3.7.0 Authentication Bypass via from-to-www-redirect |
| CVE-2026-88007 | 9.1 CRITICAL | Traefik HTTP/3 Backend NTLM Connection Reuse |
| CVE-2026-88009 | 8.8 HIGH | Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing |
| CVE-2026-88004 | 7.0 HIGH | Traefik entrypoint header-name sanitization bypassed via request trailers |
| CVE-2026-88008 | 7.0 HIGH | Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') |
| CVE-2026-88879 | 5.3 MEDIUM | Traefik before v2.11.56 Identity Spoofing via Header Alias |
| CVE-2026-88011 | 5.3 MEDIUM | Traefik: ForwardAuth identity spoofing via dot-form header alias |
| CVE-2026-88012 | 5.3 MEDIUM | Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body upload |
No comments yet