CVE-2026-88008
Traefik request smuggling and incorrect authorization from inconsistent HTTP request interpretation between Traefik and the backend (CVSS 7.0)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.11.26, < 2.11.57
- Affected versions
- Traefik ≥ 3.4.2, < 3.7.13
- Fixed in
- Traefik 2.11.57
- Fixed in
- Traefik 3.7.13
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-w4v4-9rw7-5326, ranges from the advisory API: v2 `>= 2.11.26, < 2.11.57`, v3 `>= 3.4.2, < 3.7.13`. Both lower bounds are the advisory's own and both are UNUSUALLY HIGH - 2.11.26 and 3.4.2, not the branch floor - because the smuggling window was introduced by a later change on each branch. Copying the ge 2.0.0 / ge 3.0.0 shape of the neighbouring rows here would flag years of builds the advisory says are fine.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-88008 (see the 2.x row for why ge 3.4.2 and not ge 3.0.0).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →