THREAT OPS › Threat News › [GHSA] GHSA-qqjf-53cj-pwvv (critical) — Traefik HTTP/3 Backend NTLM Connection Reuse
[GHSA] GHSA-qqjf-53cj-pwvv (critical) — Traefik HTTP/3 Backend NTLM Connection Reuse
GHSA-qqjf-53cj-pwvv Severity: critical CVE: CVE-2026-88007
Traefik HTTP/3 Backend NTLM Connection Reuse
## Summary
Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS handler chain and reaches the same ba
MITRE ATT&CK techniques
- CredentialsT1589.001
Indicators of compromise
- f2d0794417e4d06343e6e7c4722143f5b34bee45sha1
- 41da8e8b79ebbe444a94f8a2a3a30895md5
- CVE-2026-88007cve
Original source: https://github.com/advisories/GHSA-qqjf-53cj-pwvv