Cross-Vhost Routing Bypass in Traefik Load Balancer
CVE-2026-88009
8.8HIGH
What is CVE-2026-88009?
Traefik, an open-source HTTP reverse proxy and load balancer, is susceptible to a vulnerability that allows for cross-vhost routing bypass and path-scoped authorization bypass. The issue arises because Traefik accepts a rootless HTTP/1 request target stored in URL.Opaque while leaving URL.Path empty. This flaw can result in access-log evasion as the opaque target is forwarded verbatim to the backend, which may interpret it incorrectly as a path. The vulnerability has been addressed in versions 2.11.57 and 3.7.13, urging users to upgrade to safeguard their systems.
Affected Version(s)
traefik < 2.11.57 < 2.11.57
traefik >= 3.0.0, < 3.7.13 < 3.0.0, 3.7.13
