Skip to content
CVSS 9.1 · CRITICAL

CVE-2026-88007Authentication Bypass in Traefik via HTTP/3

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.

View on NVD

Analysis

A critical flaw in Traefik's HTTP/3 implementation allows attackers to reuse authenticated backend connections (NTLM/Negotiate). This enables unauthorized clients to hijack sessions and act as other users without credentials. Update to version 2.11.57 or 3.7.13 immediately if you use HTTP/3.

Relevant roles

ciberseguridadCloudBackendKubernetesDockerGo

Severity

Score: 9.1(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: NONE
Weakness (CWE): CWE-287CWE-863

EPSS

Probability of exploitation (next 30 days): 0.0037 (0.4%)
Percentile: 30.5%
EPSS: 2026-09-14

Affects

traefik:traefik

Technical description

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.

Published: 9/10/2026, 3:17:56 PM
Last modified: 9/14/2026, 7:58:52 PM

References

InicioEventosBlogRecursosCursosEquipo