Impact
Traefik, an open‑source HTTP reverse proxy, improperly handles rootless HTTP/1 request targets, storing them in URL.Opaque while leaving URL.Path empty. When rewriteRequestBuilder normalizes the path to "/", it evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against this sanitized path but forwards the opaque target verbatim to the backend. This allows an attacker to send requests that bypass path‑scoped authorization, middleware guards, and access‑log generation, potentially exposing backend services and sensitive data.
Affected Systems
All installations of Traefik prior to version 2.11.57 and 3.7.13 are vulnerable. This includes the traefik:traefik product across both major releases, regardless of operating environment. The issue remains until the corresponding patch version names are applied.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score of 0.0027 (approximately 0.27%) indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker can send a crafted HTTP/1 request with a rootless target to a publicly accessible Traefik instance. This request is normalized to a path of "/", so routing and middleware checks are performed on "/", but the opaque request target is forwarded verbatim to the backend. As a result, the attacker bypasses path‑scoped authorization, middleware guards, and access logging, gaining unauthorized access to backend services that interpret the opaque target as a path. While no public exploit references exist, the conditions for exploitation are sufficient for any Traefik instance that accepts HTTP/1 requests, sustaining a high‑level risk.
OpenCVE Enrichment
Github GHSA