THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-qqjf-53cj-pwvv (critical) — Traefik HTTP/3 Backend NTLM Connection Reuse

[GHSA] GHSA-qqjf-53cj-pwvv (critical) — Traefik HTTP/3 Backend NTLM Connection Reuse

highgithub_advisoriesPublished 2026-09-10

GHSA-qqjf-53cj-pwvv Severity: critical CVE: CVE-2026-88007

Traefik HTTP/3 Backend NTLM Connection Reuse

## Summary

Traefik's HTTP/3 request path did not initialize the connection-scoped backend transport holder that isolates connection-bound NTLM and Negotiate (Kerberos) authentication on the HTTP/1.1 and HTTP/2 paths. The HTTP/3 entrypoint reuses the HTTPS handler chain and reaches the same ba

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-qqjf-53cj-pwvv