← All CVEs NewScan detects
high

CVE-2026-88004

Traefik entrypoint header-name sanitization bypassed via request trailers - a header Traefik strips or rewrites on the request can be reintroduced in the HTTP trailer section, which the sanitizer never inspects (CVSS 7.0)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 3.2.0, < 3.7.13
Fixed in
Traefik 3.7.13
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-v67p-phpq-fc8x, advisory API lists ONE package range only, v3 `>= 3.2.0, < 3.7.13`, and no v2 arm at all - trailer handling on the entrypoint is a 3.2+ code path. One arm; adding a 2.x arm to match its same-day siblings would assert a branch the advisory does not list.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →