Skip to finding
§
High
Edge — Traefik
Confirmed
CVE-2026-88009

A rootless HTTP request target can bypass Traefik path authorization and reach protected backend routes.

Traefik authorizes empty parsed path fields while the backend receives the attacker-controlled opaque target.

Affects

Traefik, a reverse proxy and Kubernetes ingress controller commonly deployed at application boundaries.

What it enables

Unauthenticated access to path-protected or alternate-virtual-host backend resources

Send an HTTP/1.x request containing a rootless opaque request target to a reachable Traefik listener→↓Go parses the target into URL.Opaque while leaving the path and authority fields inspected by Traefik empty→↓Traefik routes and authorizes the request as path / while retaining the opaque value→↓The backend interprets the forwarded opaque target as a protected path or different virtual host
Why this matters

Traefik leads even though the impact rank placed Samsung second: Traefik’s ingress-to-impact path is reproduced in public code, while Samsung has not disclosed how an image reaches its decoder, whether interaction is required, or which process executes it.

Detail, proof-of-concept code and 4 sources
Required access

Network reachability to a Traefik HTTP/1.x listener whose backend relies on Traefik path or virtual-host policy

Affected versions

Traefik v2 before 2.11.57, Traefik v3.0.0 through 3.7.12

Proof of concept

Public exploit code →

Go stores the rootless request target in URL.Opaque while leaving the path and authority fields inspected by Traefik empty.

Traefik can consequently approve the request as path / and forward the opaque value to a backend that interprets it as a protected path or another virtual host.

The patch rejects opaque targets at entry and clears URL.Opaque before proxying; fixed releases are available.

Evidence
The public advisory reports end-to-end reproduction of cross-vhost routing, path-authorization bypass, and access-log evasionThe upstream pull request adds an entry-point rejection and clears URL.Opaque before proxyingThe upstream releases identify the advisory and fix
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Saturday, September 12, 2026