<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-06T22:34:26.959078+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-366479</id>
    <title>EUVD-2026-366479</title>
    <updated>2026-10-06T22:34:27.005313+00:00</updated>
    <content>EUVD-2026-366479</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-366479"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88008</id>
    <title>fkie_cve-2026-88008</title>
    <updated>2026-10-06T22:34:27.005349+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-88008"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w4v4-9rw7-5326</id>
    <title>GHSA-w4v4-9rw7-5326 — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization</title>
    <updated>2026-10-06T22:34:27.005385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik/v2</p>
<p>## Summary</p>
<p>There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upgrade: h2c` request header and its connection-specific `HTTP2-Settings` header were forwarded to the backend. A backend that honours the h2c upgrade and answers `101 Switching Protocols` puts Traefik into a raw byte tunnel that bypasses the router and the entire middleware chain (authentication, IPAllowList, rate limiting) on a shared backend. The fix stops forwarding the `Upgrade: h2c` token and the `HTTP2-Settings` header; `Upgrade: websocket` is unaffected. Exploitation requires a backend that upgrades h2c without validating the `Connection` listing; common off-the-shelf servers were not exploitable in testing.</p>
<p>Traefik v3.4.2 through v3.6 are end-of-life and are also affected; users on those versions must upgrade to v3.7.13.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.57
- https://github.com/traefik/traefik/releases/tag/v3.7.13</p>
<p>## For more information</p>
<p>If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p># Summary</p>
<p>Traefik's default HTTP reverse proxy forwards arbitrary `Connection: Upgrade` / `Upgrade: &lt;token&gt;` requests to the backend. Upgrade tokens are not restricted to protocols explicitly supported…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w4v4-9rw7-5326"/>
  </entry>
</feed>
