All verified exploits

CVE-2026-88007 Session Hijack via Traefik HTTP/3 Shared Backend Transport

Deterministic critical Traefik Added cve-verified-cve-2026-88007

Detects Traefik 2.11.0 through 2.11.56 and 3.0.0 through 3.7.12, where the HTTP/3 entrypoint builds its QUIC connection context without calling service.AddTransportOnContext. The per-connection RoundTripper holder is therefore missing from every HTTP/3 request context, so kerberosRoundTripper cannot pin a transport dedicated to the frontend connection and keeps using the shared backend transport. Against a backend that answers 401 WWW-Authenticate: NTLM or Negotiate — schemes that bind authentication to the TCP connection rather than to the request — backend keep-alive then lets an unrelated HTTP/3 client be served on the connection a victim authenticated, reading victim-only data and acting as that victim without ever holding their credentials. The verifier reads the version from the Traefik API and confirms the HTTP/3 precondition from /api/entrypoints or an Alt-Svc h3 advertisement. Patched in 2.11.57 and 3.7.13.

Is your app exploitable through CVE-2026-88007?

Scan your domain free