← All CVEs NewScan detects
critical

CVE-2026-88877

Traefik Kubernetes Ingress NGINX provider authentication bypass - an Ingress carrying both an auth annotation and from-to-www-redirect generates a sibling host-only router that reaches the protected backend with NO annotation-derived middleware, so a non-numeric port in the Host header (`Host: www.example.com:x`) discards BasicAuth and source-IP allowlisting alike (CVSS 9.3)

Severity
critical
Affected product
Traefik
Affected versions
Traefik ≥ 3.7.0, < 3.7.12
Fixed in
Traefik 3.7.12
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-9rch-gvf7-hrfc. Ranges read from the GitHub advisory API, not from the CVE prose: `>= v3.7.0 and <= v3.7.11`, fixed in v3.7.12, and the advisory states explicitly that v2 and every v3 before 3.7.0 are NOT affected - so ONE arm, the same shape as its 3.7-only neighbour CVE-2026-85596 and for the same reason (the Ingress NGINX provider only exists in 3.7). NOTE the bound is 3.7.12, NOT the 3.7.13 of the four smuggling/NTLM rows added the same day: today's Traefik drop has two patch lines and copying one bound across the batch would claim a patched 3.7.12 is vulnerable. MEASURED 2026-09-11 against traefik:v3.7.11 --api.insecure=true on loopback: GET /api/version -> 200 Version 3.7.11, inside this row. Negative case on traefik:v3.7.13: outside this row and outside every other Traefik row here.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →