Vulnerability Report: GO-2026-6468
- CVE-2026-88008, GHSA-w4v4-9rw7-5326
- Affects: github.com/traefik/traefik, github.com/traefik/traefik/v2, and 1 more
- Published: Sep 16, 2026
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization in github.com/traefik/traefik
For detailed information about this vulnerability, visit https://github.com/traefik/traefik/security/advisories/GHSA-w4v4-9rw7-5326 or https://nvd.nist.gov/vuln/detail/CVE-2026-88008.
Affected Packages
-
PathVersionsSymbols
Aliases
References
- https://github.com/traefik/traefik/security/advisories/GHSA-w4v4-9rw7-5326
- https://nvd.nist.gov/vuln/detail/CVE-2026-88008
- https://github.com/traefik/traefik/commit/a277e94664ffc1ce9543df552d3bbf48d4d3b8b3
- https://github.com/traefik/traefik/pull/13797
- https://github.com/traefik/traefik/releases/tag/v2.11.57
- https://github.com/traefik/traefik/releases/tag/v3.7.13
- https://vuln.go.dev/ID/GO-2026-6468.json
Feedback
See anything missing or incorrect?
Suggest an edit to this report.