Description
Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against a path normalized to / but forwards URL.Opaque verbatim to the backend, allowing cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion when the backend interprets the opaque target as a path. This issue is fixed in 2.11.57 and 3.7.13.
Published: 2026-09-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Path bypass exposing backend routes and evading authorization and logging
Action: Patch Now
AI Analysis

Impact

Traefik, an open‑source HTTP reverse proxy, improperly handles rootless HTTP/1 request targets, storing them in URL.Opaque while leaving URL.Path empty. When rewriteRequestBuilder normalizes the path to "/", it evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against this sanitized path but forwards the opaque target verbatim to the backend. This allows an attacker to send requests that bypass path‑scoped authorization, middleware guards, and access‑log generation, potentially exposing backend services and sensitive data.

Affected Systems

All installations of Traefik prior to version 2.11.57 and 3.7.13 are vulnerable. This includes the traefik:traefik product across both major releases, regardless of operating environment. The issue remains until the corresponding patch version names are applied.

Risk and Exploitability

The CVSS score of 8.8 classifies the vulnerability as high severity. The EPSS score of 0.0027 (approximately 0.27%) indicates a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that an attacker can send a crafted HTTP/1 request with a rootless target to a publicly accessible Traefik instance. This request is normalized to a path of "/", so routing and middleware checks are performed on "/", but the opaque request target is forwarded verbatim to the backend. As a result, the attacker bypasses path‑scoped authorization, middleware guards, and access logging, gaining unauthorized access to backend services that interpret the opaque target as a path. While no public exploit references exist, the conditions for exploitation are sufficient for any Traefik instance that accepts HTTP/1 requests, sustaining a high‑level risk.

Generated by OpenCVE AI on September 23, 2026 at 01:55 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Traefik to version 2.11.57 or later, or to 3.7.13 or later, as these releases contain the fix for URL.Opaque handling.
  • Immediately restrict the formation of HTTP/1 rootless request targets by disabling or filtering such requests in the entrypoint configuration, ensuring that all requests contain a standard path component.
  • Verify that the backend services correctly interpret incoming request targets as paths rather than opaque values, and implement input validation to reject or sanitize unexpected target formats.

Generated by OpenCVE AI on September 23, 2026 at 01:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-f52w-8j3h-j724 Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
History

Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-551
References
Metrics threat_severity

None

threat_severity

Important


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Fri, 11 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Traefik
Traefik traefik
Vendors & Products Traefik
Traefik traefik

Thu, 10 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Description Traefik is an open source HTTP reverse proxy and load balancer. Prior to 2.11.57, and 3.7.13, Traefik accepts a rootless HTTP/1 request target that Go stores in URL.Opaque while leaving URL.Path empty. The rewriteRequestBuilder path evaluates routing, path sanitization, forwardAuth, encodedCharacters, and access logging against a path normalized to / but forwards URL.Opaque verbatim to the backend, allowing cross-vhost routing bypass, path-scoped authorization bypass, and access-log evasion when the backend interprets the opaque target as a path. This issue is fixed in 2.11.57 and 3.7.13.
Title Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging
Weaknesses CWE-1286
CWE-444
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-10T15:40:16.096Z

Reserved: 2026-09-09T19:19:27.406Z

Link: CVE-2026-88009

cve-icon Vulnrichment

Updated: 2026-09-10T15:40:12.058Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-10T16:18:07.780

Modified: 2026-09-14T19:59:14.810

Link: CVE-2026-88009

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-10T15:01:56Z

Links: CVE-2026-88009 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T02:00:10Z

Weaknesses
  • CWE-1286

    Improper Validation of Syntactic Correctness of Input

  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')

  • CWE-551

    Incorrect Behavior Order: Authorization Before Parsing and Canonicalization