- Sources: advisory, 3.7.13 release, 2.11.57 release
- Summary: Traefik forwards arbitrary HTTP upgrade tokens to the backend, tracked as CVE-2026-88008 at High severity and CVSS v4 7.0, so where the backend itself accepts
Upgrade: h2c and answers 101 Switching Protocols an unauthenticated request to an unprotected route opens a raw tunnel whose requests skip BasicAuth, ForwardAuth, IPAllowList and RateLimit and leave no entry in Traefik's access logs, metrics or traces. The advisory states the backend's ability to accept the client-initiated upgrade is a required prerequisite, that common off-the-shelf servers were not exploitable in testing, and that a current Go h2c server on recent golang.org/x/net implementations is not necessarily affected, because those implementations no longer support the HTTP/1.1 upgrade mechanism. Affected ranges are v2 from 2.11.26 up to but not including 2.11.57, and v3 from 3.4.2 up to but not including 3.7.13, with 2.11.57 and 3.7.13 the first patched releases, and the advisory states 3.4.2 through 3.6 are end of life and also affected, so operators there must upgrade to 3.7.13. - Why it matters: On a backend that answers the upgrade, one unprotected route voids the middleware protections on the other routes, and the bypassed traffic leaves no trace in the proxy's own telemetry.
send feedback on this story