Contact Zero

CVE-2026-88008

traefik traefik

score 30Public PoC ×1HIGH 7

Summary

Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.

Published 2026-09-10 · first seen here 2026-10-10

Analysis & write-ups

No technical write-up from a research team yet. Contact Zero checks Unit 42, Google/Mandiant, Microsoft, Talos, CrowdStrike, Rapid7, watchTowr and others several times a day, plus NVD and CISA reference links.

Exploit availability

Public exploit code lowers the bar for attackers, so prioritise patching and hunting. These repositories are unverified. Fake PoCs that contain malware are common, so never run them outside an isolated lab.

Where it shows in your logs

Server or web application · Authentication bypass or missing authorisation medium confidence

What to look for

Data sources

Web server and WAF logs · ATT&CK DS0015 Application Log Content

Sentinel
W3CIISLogAppServiceHTTPLogsAzureDiagnostics (Application Gateway / Front Door WAF)_Im_WebSession
Splunk
Web.Webms:iis:autoaccess_combinedWAF / proxy sourcetypes
CrowdStrike
Falcon Next-Gen SIEM: third-party web / WAF / proxy logs

Process creation · ATT&CK DS0009 Process Creation

Sentinel
DeviceProcessEventsSecurityEvent (4688)Sysmon Event ID 1_Im_ProcessCreate
Splunk
Endpoint.ProcessesXmlWinEventLog:Microsoft-Windows-Sysmon/OperationalWinEventLog:Security (4688)
CrowdStrike
ProcessRollup2SyntheticProcessRollup2

File creation · ATT&CK DS0022 File Creation

Sentinel
DeviceFileEventsSysmon Event ID 11_Im_FileEvent
Splunk
Endpoint.FilesystemSysmon Event ID 11
CrowdStrike
NewExecutableWrittenNewScriptWritten*FileWritten events

Network connections · ATT&CK DS0029 Network Connection Creation / Network Traffic Flow

Sentinel
DeviceNetworkEventsCommonSecurityLog (firewall)_Im_NetworkSession
Splunk
Network_Traffic.All_TrafficFirewall sourcetypes (pan:traffic, fortigate_traffic, cisco:asa)
CrowdStrike
NetworkConnectIP4NetworkReceiveAcceptIP4NetworkConnectIP6

Authentication and sessions · ATT&CK DS0028 Logon Session Creation / DS0002 User Account Authentication

Sentinel
SigninLogsSecurityEvent (4624, 4625, 4648)DeviceLogonEventsIdentityLogonEvents_Im_Authentication
Splunk
Authentication.Authenticationpan:globalprotectVPN sourcetypes
CrowdStrike
UserLogonUserLogonFailed2Falcon Identity Protection events

Account and group changes · ATT&CK DS0002 User Account Creation / Modification

Sentinel
SecurityEvent (4720, 4728, 4732, 4756)AuditLogsIdentityDirectoryEvents
Splunk
Change.All_Changes (Account_Management)WinEventLog:Security (4720, 4732)
CrowdStrike
UserAccountCreatedUserAccountAddedToGroup

A generic baseline worked out from the product type and weakness (CWE-444, CWE-863), not a detection. Check table and field names against your environment. Hunt queries for Sigma, Splunk, Sentinel and CrowdStrike are coming.

References