Cross-Vhost Routing Bypass in Traefik Load Balancer
CVE-2026-88009

8.8HIGH

Key Information:

Vendor

Traefik

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-88009?

Traefik, an open-source HTTP reverse proxy and load balancer, is susceptible to a vulnerability that allows for cross-vhost routing bypass and path-scoped authorization bypass. The issue arises because Traefik accepts a rootless HTTP/1 request target stored in URL.Opaque while leaving URL.Path empty. This flaw can result in access-log evasion as the opaque target is forwarded verbatim to the backend, which may interpret it incorrectly as a path. The vulnerability has been addressed in versions 2.11.57 and 3.7.13, urging users to upgrade to safeguard their systems.

Affected Version(s)

traefik < 2.11.57 < 2.11.57

traefik >= 3.0.0, < 3.7.13 < 3.0.0, 3.7.13

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.