high
CVE-2026-88004
Traefik entrypoint header-name sanitization bypassed via request trailers - a header Traefik strips or rewrites on the request can be reintroduced in the HTTP trailer section, which the sanitizer never inspects (CVSS 7.0)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 3.2.0, < 3.7.13
- Fixed in
- Traefik 3.7.13
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-v67p-phpq-fc8x, advisory API lists ONE package range only, v3 `>= 3.2.0, < 3.7.13`, and no v2 arm at all - trailer handling on the entrypoint is a 3.2+ code path. One arm; adding a 2.x arm to match its same-day siblings would assert a branch the advisory does not list.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →