{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/traefik-v3.4.2---v3.6/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-88007"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Traefik (v2.11.0-v2.11.56)","Traefik (v3.0.0-v3.7.12)","Traefik (\u003c v2.11.57)","Traefik (v3.4.2 - v3.6)"],"_cs_severities":["critical"],"_cs_tags":["vulnerability","auth-bypass","webserver","proxy","request-smuggling","authorization-bypass"],"_cs_type":"advisory","_cs_vendors":["Traefik"],"content_html":"\u003cp\u003eTraefik (v2.11.0-v2.11.56 and v3.0.0-v3.7.12) contains a critical authorization bypass vulnerability (CVE-2026-88007) when configured with HTTP/3. The vulnerability stems from a protocol-parity gap where the HTTP/3 entrypoint fails to initialize a connection-scoped transport holder, unlike the HTTP/1.1 and HTTP/2 paths.\u003c/p\u003e\n\u003cp\u003eWhen using backends that utilize connection-bound authentication mechanisms such as NTLM or Negotiate (Kerberos), the \u003ccode\u003ekerberosRoundTripper\u003c/code\u003e relies on \u003ccode\u003eservice.AddTransportOnContext\u003c/code\u003e to isolate authenticated connections. Because this initialization is absent in the HTTP/3 \u003ccode\u003eConnContext\u003c/code\u003e, the round-tripper falls back to a shared backend transport pool. As a result, once a victim establishes an authenticated session to a backend that supports keep-alive, an unrelated HTTP/3 client may be assigned the same persistent backend TCP connection. This allows the second client to inherit the victim's backend identity, enabling unauthorized access to data and the ability to perform state-changing requests without providing the victim's credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for complete cross-client authorization bypass on affected routes. An unauthenticated attacker can masquerade as a previously authenticated victim, enabling the theft of victim-only data and the execution of unauthorized actions (e.g., balance transfers or configuration changes). This affects enterprise environments utilizing NTLM or Kerberos authentication integrated with Traefik proxies and HTTP/3.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Traefik to v2.11.57 or v3.7.13 immediately to ensure the \u003ccode\u003eConnContext\u003c/code\u003e properly initializes the connection-scoped transport holder.\u003c/li\u003e\n\u003cli\u003eAs a temporary mitigation, disable HTTP/3 support on Traefik entrypoints that route to backends relying on connection-bound NTLM or Negotiate authentication until patches are applied.\u003c/li\u003e\n\u003cli\u003eAudit backend configurations to identify services using persistent NTLM/Negotiate authentication and verify that they are not exposed via HTTP/3 entrypoints in the interim.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-11T00:53:36Z","date_published":"2026-09-11T00:52:59Z","id":"https://feed.craftedsignal.io/briefs/2026-09-traefik-http3-auth-bypass/","summary":"Traefik fails to isolate connection-bound NTLM and Negotiate authentication on HTTP/3 routes, allowing unrelated clients to inherit victim-authenticated backend connections.","title":"Traefik HTTP/3 Backend Authentication Bypass via Connection Reuse","url":"https://feed.craftedsignal.io/briefs/2026-09-traefik-http3-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Traefik (V3.4.2 - V3.6)","version":"https://jsonfeed.org/version/1.1"}