THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-w4v4-9rw7-5326 (high) — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

[GHSA] GHSA-w4v4-9rw7-5326 (high) — Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

highgithub_advisoriesPublished 2026-09-10

GHSA-w4v4-9rw7-5326 Severity: high CVE: CVE-2026-88008

Traefik: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') and Incorrect Authorization

## Summary

There is a high-severity request-smuggling vulnerability in Traefik's handling of the HTTP/1.1 `Upgrade` mechanism. Since Traefik moved to unencrypted HTTP/2 with prior knowledge (Go 1.24), a client-initiated `Upg

Indicators of compromise

Original source: https://github.com/advisories/GHSA-w4v4-9rw7-5326