CVE-2026-88009
Traefik rootless HTTP/1 request-target is routed as "/" but forwarded to the backend verbatim - Go parks a rootless target in URL.Opaque, so path-scoped routing rules, path-scoped middleware (auth, allowlists, rate limits) and the access log all see "/" while the backend receives the real path (CVSS 8.8)
- Severity
- high
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.0.0, < 2.11.57
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.13
- Fixed in
- Traefik 2.11.57
- Fixed in
- Traefik 3.7.13
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-f52w-8j3h-j724, ranges from the advisory API: v2 `< 2.11.57`, v3 `>= 3.0.0, < 3.7.13`. The v2 range states no lower bound, so this arm uses the file's standing convention - ge 2.0.0, which deliberately does not claim 1.x: the module path the advisory scopes is github.com/traefik/traefik/v2, and under-reporting an unmaintained 1.x beats asserting a range the advisory does not state.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-88009 (see the 2.x row).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →