CVE-2026-71324
Traefik cross-user response poisoning via proxied CONNECT (HTTP/2/3 CONNECT smuggled into the backend keep-alive pool)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.0.0, < 2.11.53
- Affected versions
- Traefik ≥ 3.0.0, < 3.6.24
- Affected versions
- Traefik ≥ 3.7.0, < 3.7.9
- Fixed in
- Traefik 2.11.53
- Fixed in
- Traefik 3.6.24
- Fixed in
- Traefik 3.7.9
- Added to NewScan
- 2026-08-23
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-08-23 with the Traefik appliances fingerprint. GHSA-3ccp-42pg-hgv6: fixed on three branches - 2.11.53, 3.6.24, 3.7.9 - so THREE per-branch rows, never one widened lt (a single bound would flag a patched 2.11.53+ as vulnerable to the 3.x bound and vice versa; the exact Confluence CVE-2023-22518 mistake). This is the 2.x arm; ge 2.0.0 deliberately does not claim 1.x - the GHSA scopes github.com/traefik/traefik/v2+, and under-reporting an unmaintained 1.x beats asserting a range the advisory does not state.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.0.0-3.6.23 arm of CVE-2026-71324 (see the 2.x row for the advisory rationale). 3.6.24 through 3.6.x are patched and sit in the deliberate gap between this row and the 3.7 arm.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.7.0-3.7.8 arm of CVE-2026-71324. Measured against traefik:v3.7.9 itself (the fixed build) while writing the fingerprint: /api/version reports 3.7.9, which is outside this row - the patched-side negative case.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →