CVE-2026-88877
Traefik Kubernetes Ingress NGINX provider authentication bypass - an Ingress carrying both an auth annotation and from-to-www-redirect generates a sibling host-only router that reaches the protected backend with NO annotation-derived middleware, so a non-numeric port in the Host header (`Host: www.example.com:x`) discards BasicAuth and source-IP allowlisting alike (CVSS 9.3)
- Severity
- critical
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 3.7.0, < 3.7.12
- Fixed in
- Traefik 3.7.12
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-9rch-gvf7-hrfc. Ranges read from the GitHub advisory API, not from the CVE prose: `>= v3.7.0 and <= v3.7.11`, fixed in v3.7.12, and the advisory states explicitly that v2 and every v3 before 3.7.0 are NOT affected - so ONE arm, the same shape as its 3.7-only neighbour CVE-2026-85596 and for the same reason (the Ingress NGINX provider only exists in 3.7). NOTE the bound is 3.7.12, NOT the 3.7.13 of the four smuggling/NTLM rows added the same day: today's Traefik drop has two patch lines and copying one bound across the batch would claim a patched 3.7.12 is vulnerable. MEASURED 2026-09-11 against traefik:v3.7.11 --api.insecure=true on loopback: GET /api/version -> 200 Version 3.7.11, inside this row. Negative case on traefik:v3.7.13: outside this row and outside every other Traefik row here.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →