Ce mail provient de l'extérieur, restons vigilants ===================================================================== CERT-Renater Note d'Information No. 2026/VULN921 _____________________________________________________________________ DATE : 23/09/2026 HARDWARE PLATFORM(S): / OPERATING SYSTEM(S): Systems running Traefik versions prior to 3.7.13, 2.11.57. ===================================================================== https://github.com/traefik/traefik/security/advisories/GHSA-qqjf-53cj-pwvv https://github.com/traefik/traefik/security/advisories/GHSA-v67p-phpq-fc8x https://github.com/traefik/traefik/security/advisories/GHSA-f52w-8j3h-j724 https://github.com/traefik/traefik/security/advisories/GHSA-w4v4-9rw7-5326 _____________________________________________________________________ Traefik HTTP/3 Backend NTLM Connection Reuse Critical kevinpollet published GHSA-qqjf-53cj-pwvv Package Traefik (Go) Affected versions >= v3.0.0, <= v3.7.12 >= v2.11.0, <= v2.11.56 Patched versions v3.7.13 v2.11.57 Description Summary Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS handler chain and reaches the same backend round-tripper, but its ConnContext never called service.AddTransportOnContext, so kerberosRoundTripper fell back to the shared backend transport instead of a per-frontend-connection pool. On a route served over HTTP/3 to a backend that binds identity to a persistent connection via NTLM or Negotiate, an unrelated HTTP/3 client could be assigned a backend connection already authenticated as a victim and inherit that identity, reading victim-only data and performing actions as the victim without presenting the victim's credentials. Affected deployments require HTTP/3 enabled on the entrypoint, a backend using connection-bound NTLM/Negotiate authentication, and backend keep-alive; deployments using ordinary per-request authentication are not affected. Patches https://github.com/traefik/traefik/releases/tag/v2.11.57 https://github.com/traefik/traefik/releases/tag/v3.7.13 For more information If you have any questions or comments about this advisory, please open an issue. Original Description Severity Critical 9.1/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity Low Attack Requirements Present Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality High Integrity High Availability None Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N CVE ID CVE-2026-88007 Weaknesses WeaknessCWE-287 WeaknessCWE-863 Credits @OneZ3r0 OneZ3r0 Reporter _____________________________________________________________________ Traefik entrypoint header-name sanitization bypassed via request trailers High kevinpollet published GHSA-v67p-phpq-fc8x Package Traefik (Go) Affected versions >= v3.2.0, <= v3.7.12 Patched versions v3.7.13 Description Summary Traefik's entrypoint defenses against spoofed trusted header names — aliasHeadersStrategy / underscoreHeadersStrategy in delete or reject mode, and the default forwardedHeaders stripping of client-supplied X-Forwarded-* — scan req.Header only and never req.Trailer. An unauthenticated client can therefore smuggle a sanitized name (an aliasing spelling such as X_Auth_User, or a trusted name such as X-Forwarded-Prefix) as an HTTP/1.1 chunked trailer or an HTTP/2 trailer: reject does not return its documented 400, delete does not remove the name, and Traefik's reverse proxy forwarded the trailer to the backend — with an attacker-chosen value whenever a body-buffering middleware (the retry middleware with status codes, or the buffering middleware) reads the body before the proxy clone. Backends that merge trailers into their header namespace then act on the smuggled name. The fix stops forwarding request trailer values to the backend; the declared trailer names are still forwarded as permitted by RFC 9110 section 6.6.2. Traefik v2 is not affected: the defect is in the custom reverse proxy introduced in v3 (pkg/proxy/httputil), and v2 uses the Go standard library's httputil.ReverseProxy, which does not forward request trailer values to the backend. Affected v3 lines from v3.2.0 through v3.7.12 include the end-of-life v3.2 through v3.6 lines, which will not receive a fix on their own line; the remedy for those users is to upgrade to v3.7.13. Patches https://github.com/traefik/traefik/releases/tag/v3.7.13 For more information If you have any questions or comments about this advisory, please open an issue. Original Description Severity High 7.0/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity High Attack Requirements None Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality None Integrity None Availability None Subsequent System Impact Metrics Confidentiality High Integrity High Availability None CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVE ID CVE-2026-88004 Weaknesses WeaknessCWE-436 WeaknessCWE-807 Credits @bipol4r bipol4r Reporter _____________________________________________________________________ Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging High kevinpollet published GHSA-f52w-8j3h-j724 Package Traefik (Go) Affected versions >= v3.0.0, <= v3.7.12 <= v2.11.56 Patched versions v3.7.13 v2.11.57 Description Summary Traefik accepts an HTTP/1.x request whose request-target is in rootless / opaque form (for example GET http:http://internal-vhost/admin HTTP/1.1). Go parses this into URL.Opaque with an empty URL.Path, so Traefik evaluates all routing, path-sanitization, middleware and access-log decisions against a path that normalizes to /, while the proxy forwards the attacker's original target byte-for-byte to the backend. Router path/prefix guards, forwardAuth path-scoped policies and the encodedCharacters hardening never see the real target, and the access log records every such request as GET / HTTP/1.1. Against a backend that resolves a rootless target as a path, this yields cross-vhost routing bypass, path-scoped authorization bypass and access-log evasion — unauthenticated, with stock entrypoint defaults. Traefik v3.0 through v3.6 are end-of-life and are also affected; they will not receive a fix on their own line. Users on those versions must upgrade to v3.7.13. Patches https://github.com/traefik/traefik/releases/tag/v2.11.57 https://github.com/traefik/traefik/releases/tag/v3.7.13 For more information If you have any questions or comments about this advisory, please open an issue. Original Description Severity High 8.8/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity Low Attack Requirements None Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality High Integrity Low Availability None Subsequent System Impact Metrics Confidentiality None Integrity None Availability None CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N CVE ID CVE-2026-88009 Weaknesses WeaknessCWE-444 WeaknessCWE-1286 _____________________________________________________________________ Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik/v3 High kevinpollet published GHSA-w4v4-9rw7-5326 Package Traefik (Go) Affected versions >= v3.4.2, <= v3.7.12 >= v2.11.26, <= v2.11.56 Patched versions v3.7.13 v2.11.57 Description Summary There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 Upgrade mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated Upgrade: h2c request header and its connection-specific HTTP2-Settings header were forwarded to the backend. A backend that honours the h2c upgrade and answers 101 Switching Protocols puts Traefik into a raw byte tunnel that bypasses the router and the entire middleware chain (authentication, IPAllowList, rate limiting) on a shared backend. The fix stops forwarding the Upgrade: h2c token and the HTTP2-Settings header; Upgrade: websocket is unaffected. Exploitation requires a backend that upgrades h2c without validating the Connection listing; common off-the-shelf servers were not exploitable in testing. Traefik v3.4.2 through v3.6 are end-of-life and are also affected; users on those versions must upgrade to v3.7.13. Patches https://github.com/traefik/traefik/releases/tag/v2.11.57 https://github.com/traefik/traefik/releases/tag/v3.7.13 For more information If you have any questions or comments about this advisory, please open an issue. Original Description Severity High 7.0/ 10 CVSS v4 base metrics Exploitability Metrics Attack Vector Network Attack Complexity Low Attack Requirements Present Privileges Required None User interaction None Vulnerable System Impact Metrics Confidentiality None Integrity None Availability None Subsequent System Impact Metrics Confidentiality High Integrity High Availability None CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N CVE ID CVE-2026-88008 Weaknesses WeaknessCWE-444 WeaknessCWE-863 Credits @ihopenre-eng ihopenre-eng Reporter ========================================================= + CERT-RENATER | tel : 01-53-94-20-44 + + 23/25 Rue Daviel | fax : 01-53-94-20-41 + + 75013 Paris | email:cert@support.renater.fr + =========================================================