criticalVulnerability

CVE-2026-88007

## Summary Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS handler chain and reaches the same backend round-tripper, but its `ConnContext` never called `service.AddTransportOnContext`, so `kerberosRoundTripper` fell back to the shared backend transport instead of a per-frontend-connection pool. On a route served over HTTP/3 to a backend that binds identity to a persistent connection via NTLM or Negotiate, an unrelated HTTP/3 client could be assigned a backend connection already authenticated as a victim and inherit that identity, reading victim-only data and performing actions as the victim without presenting the victim's credentials. Affected deployments require HTTP/3 enabled on the entrypoint, a backend using connection-bound NTLM/Negotiate authentication, and backend keep-alive; deployments using ordinary per-request authentication are not affected. ## Patches - https://github.com/traefik/traefik/releases/tag/v2.11.57 - https://github.com/traefik/traefik/releases/tag/v3.7.13 ## For more information If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues). <details> <summary>Original Description</summary> ## Traefik HTTP/3 Backend NTLM Connection Reuse ### Summary Traefik's HTTP/3 request path does not initialize the connection-scoped backend transport state that Traefik uses to isolate connection-bound NTLM and Negotiate authentication for HTTP/1.1 and HTTP/2. When a backend keeps authenticated identity on a persistent HTTP/1.1 TCP connection, an unrelated HTTP/3 client can reuse a victim-authenticated backend connection and inherit that backend identity. In the attached reproduction, the HTTPS/HTTP/1.1 control case behaves correctly and isolates the attacker, but the HTTP/3 case allows a seco

Properties

ghsa_id
GHSA-qqjf-53cj-pwvv
severity
critical
summary
Traefik HTTP/3 Backend NTLM Connection Reuse
cve_id
CVE-2026-88007
is_ghsa_only
false
ghsa_published
2026-09-10T23:04:06Z
source_url
https://github.com/advisories/GHSA-qqjf-53cj-pwvv
ghsa_updated
2026-09-10T23:04:07Z

Related Entities (7)

VULNERABLE_TO (2)

[Software]go/github.com/traefik/traefik/v3
[Software]go/github.com/traefik/traefik/v2

AFFECTS (2)

[Software]go/github.com/traefik/traefik/v2
[Software]go/github.com/traefik/traefik/v3

HAS_WEAKNESS (2)

[Weakness]Improper Authentication
[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-88007 — Ninja Signal Threat Intelligence | Ninja Signal