← All CVEs NewScan detects
high

CVE-2026-88009

Traefik rootless HTTP/1 request-target is routed as "/" but forwarded to the backend verbatim - Go parks a rootless target in URL.Opaque, so path-scoped routing rules, path-scoped middleware (auth, allowlists, rate limits) and the access log all see "/" while the backend receives the real path (CVSS 8.8)

Severity
high
Affected product
Traefik
Affected versions
Traefik ≥ 2.0.0, < 2.11.57
Affected versions
Traefik ≥ 3.0.0, < 3.7.13
Fixed in
Traefik 2.11.57
Fixed in
Traefik 3.7.13
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-f52w-8j3h-j724, ranges from the advisory API: v2 `< 2.11.57`, v3 `>= 3.0.0, < 3.7.13`. The v2 range states no lower bound, so this arm uses the file's standing convention - ge 2.0.0, which deliberately does not claim 1.x: the module path the advisory scopes is github.com/traefik/traefik/v2, and under-reporting an unmaintained 1.x beats asserting a range the advisory does not state.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-88009 (see the 2.x row).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →