<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:04:12 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-366479</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-366479</link>
      <description>EUVD-2026-366479</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-366479</guid>
    </item>
    <item>
      <title>fkie_cve-2026-88008</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-88008</link>
      <description>&lt;p&gt;Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.26 until 2.11.57 and 3.7.13, Traefik forwards a client-supplied Connection header requesting Upgrade, the Upgrade: h2c token, and HTTP2-Settings to a shared backend. If the backend accepts h2c and returns 101 Switching Protocols, Traefik enters a raw tunnel and no longer applies routers, BasicAuth, ForwardAuth, IPAllowList, RateLimit, access logging, metrics, or tracing to later HTTP/2 requests, allowing an unauthenticated request through an unprotected route to reach protected paths on the same backend. This issue is fixed in 2.11.57 and 3.7.13.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-88008</guid>
    </item>
    <item>
      <title>GHSA-w4v4-9rw7-5326 — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-w4v4-9rw7-5326</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high-severity request-smuggling vulnerability in Traefik&amp;#39;s handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upgrade: h2c` request header and its connection-specific `HTTP2-Settings` header were forwarded to the backend. A backend that honours the h2c upgrade and answers `101 Switching Protocols` puts Traefik into a raw byte tunnel that bypasses the router and the entire middleware chain (authentication, IPAllowList, rate limiting) on a shared backend. The fix stops forwarding the `Upgrade: h2c` token and the `HTTP2-Settings` header; `Upgrade: websocket` is unaffected. Exploitation requires a backend that upgrades h2c without validating the `Connection` listing; common off-the-shelf servers were not exploitable in testing.&lt;/p&gt;
&lt;p&gt;Traefik v3.4.2 through v3.6 are end-of-life and are also affected; users on those versions must upgrade to v3.7.13.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.57
- https://github.com/traefik/traefik/releases/tag/v3.7.13&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s default HTTP reverse proxy forwards arbitrary `Connection: Upgrade` / `Upgrade: &amp;lt;token&amp;gt;` requests to the backend. Upgrade tokens are not restricted to protocols explicitly supported…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v3, Go: github.com/traefik/traefik/v2&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;There is a high-severity request-smuggling vulnerability in Traefik&amp;#39;s handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upgrade: h2c` request header and its connection-specific `HTTP2-Settings` header were forwarded to the backend. A backend that honours the h2c upgrade and answers `101 Switching Protocols` puts Traefik into a raw byte tunnel that bypasses the router and the entire middleware chain (authentication, IPAllowList, rate limiting) on a shared backend. The fix stops forwarding the `Upgrade: h2c` token and the `HTTP2-Settings` header; `Upgrade: websocket` is unaffected. Exploitation requires a backend that upgrades h2c without validating the `Connection` listing; common off-the-shelf servers were not exploitable in testing.&lt;/p&gt;
&lt;p&gt;Traefik v3.4.2 through v3.6 are end-of-life and are also affected; users on those versions must upgrade to v3.7.13.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.57
- https://github.com/traefik/traefik/releases/tag/v3.7.13&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;# Summary&lt;/p&gt;
&lt;p&gt;Traefik&amp;#39;s default HTTP reverse proxy forwards arbitrary `Connection: Upgrade` / `Upgrade: &amp;lt;token&amp;gt;` requests to the backend. Upgrade tokens are not restricted to protocols explicitly supported…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-w4v4-9rw7-5326</guid>
    </item>
  </channel>
</rss>
