← All CVEs NewScan detects
high

CVE-2026-71324

Traefik cross-user response poisoning via proxied CONNECT (HTTP/2/3 CONNECT smuggled into the backend keep-alive pool)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 2.0.0, < 2.11.53
Affected versions
Traefik ≥ 3.0.0, < 3.6.24
Affected versions
Traefik ≥ 3.7.0, < 3.7.9
Fixed in
Traefik 2.11.53
Fixed in
Traefik 3.6.24
Fixed in
Traefik 3.7.9
Added to NewScan
2026-08-23
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-08-23 with the Traefik appliances fingerprint. GHSA-3ccp-42pg-hgv6: fixed on three branches - 2.11.53, 3.6.24, 3.7.9 - so THREE per-branch rows, never one widened lt (a single bound would flag a patched 2.11.53+ as vulnerable to the 3.x bound and vice versa; the exact Confluence CVE-2023-22518 mistake). This is the 2.x arm; ge 2.0.0 deliberately does not claim 1.x - the GHSA scopes github.com/traefik/traefik/v2+, and under-reporting an unmaintained 1.x beats asserting a range the advisory does not state.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.0.0-3.6.23 arm of CVE-2026-71324 (see the 2.x row for the advisory rationale). 3.6.24 through 3.6.x are patched and sit in the deliberate gap between this row and the 3.7 arm.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.7.0-3.7.8 arm of CVE-2026-71324. Measured against traefik:v3.7.9 itself (the fixed build) while writing the fingerprint: /api/version reports 3.7.9, which is outside this row - the patched-side negative case.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →