CVE-2026-88007

Source
https://cve.org/CVERecord?id=CVE-2026-88007
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88007.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-88007
Aliases
Downstream
Published
2026-09-10T14:47:28Z
Modified
2026-09-12T03:47:21Z
Severity
  • 9.1 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Traefik HTTP/3 Backend NTLM Connection Reuse
Details

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-287",
        "CWE-863"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/88xxx/CVE-2026-88007.json"
}
References

Affected packages

Git / github.com/traefik/traefik

Affected ranges

Type
GIT
Repo
https://github.com/traefik/traefik
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.11.0"
        },
        {
            "fixed": "2.11.57"
        },
        {
            "introduced": "3.0.0"
        },
        {
            "fixed": "3.7.13"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v2.*
v2.11.0
v2.11.1
v2.11.10
v2.11.11
v2.11.12
v2.11.13
v2.11.14
v2.11.15
v2.11.16
v2.11.17
v2.11.18
v2.11.19
v2.11.2
v2.11.20
v2.11.21
v2.11.22
v2.11.23
v2.11.24
v2.11.25
v2.11.26
v2.11.27
v2.11.28
v2.11.29
v2.11.3
v2.11.30
v2.11.31
v2.11.32
v2.11.33
v2.11.34
v2.11.35
v2.11.36
v2.11.37
v2.11.38
v2.11.39
v2.11.4
v2.11.40
v2.11.41
v2.11.42
v2.11.43
v2.11.44
v2.11.45
v2.11.46
v2.11.47
v2.11.48
v2.11.49
v2.11.5
v2.11.50
v2.11.51
v2.11.52
v2.11.53
v2.11.54
v2.11.55
v2.11.56
v2.11.6
v2.11.7
v2.11.8
v2.11.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-88007.json"