THREAT OPS › Threat News › [GHSA] GHSA-w4v4-9rw7-5326 (high) — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
[GHSA] GHSA-w4v4-9rw7-5326 (high) — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
GHSA-w4v4-9rw7-5326 Severity: high CVE: CVE-2026-88008
Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization
## Summary
There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upg
Indicators of compromise
- CVE-2026-88008cve
- http://127.0.0.1:9900url
- http://x/adminurl
- golang.orgdomain
Original source: https://github.com/advisories/GHSA-w4v4-9rw7-5326