← All CVEs NewScan detects
high

CVE-2026-88008

Traefik request smuggling and incorrect authorization from inconsistent HTTP request interpretation between Traefik and the backend (CVSS 7.0)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 2.11.26, < 2.11.57
Affected versions
Traefik ≥ 3.4.2, < 3.7.13
Fixed in
Traefik 2.11.57
Fixed in
Traefik 3.7.13
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-w4v4-9rw7-5326, ranges from the advisory API: v2 `>= 2.11.26, < 2.11.57`, v3 `>= 3.4.2, < 3.7.13`. Both lower bounds are the advisory's own and both are UNUSUALLY HIGH - 2.11.26 and 3.4.2, not the branch floor - because the smuggling window was introduced by a later change on each branch. Copying the ge 2.0.0 / ge 3.0.0 shape of the neighbouring rows here would flag years of builds the advisory says are fine.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-88008 (see the 2.x row for why ge 3.4.2 and not ge 3.0.0).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →