BlackTree Security · Infrastructure · Automation · AI

A Traefik Shortcut Could Let a Stranger Inherit Your Login

A Traefik HTTP/3 proxy should keep two visitors’ identities separate, even when it reuses connections to make their requests faster. A Traefik advisory published on 7 September 2026 shows a narrow but serious exception: a second HTTP/3 client can be assigned a backend connection that a different client has already authenticated through NTLM or Negotiate. On that connection, the backend can treat the stranger as the victim.

This is CVE-2026-88007, scored 9.1 under CVSS 4.0 in the Traefik-maintained advisory. The published reproduction demonstrates a victim-only read and a state-changing action from a second client without the victim’s credentials. It is a public proof of concept, not confirmation of malicious exploitation in production.

The login was attached to the connection

The precise configuration matters. HTTP/3 must be enabled on a Traefik entrypoint. The routed backend must rely on connection-bound NTLM or Negotiate authentication. Backend keep-alive and connection reuse must also be active, and the attacker must reach the same route. Ordinary per-request authentication does not fit this vulnerability.

NTLM and Negotiate can associate an authenticated identity with a persistent backend TCP connection. For HTTP/1.1 and HTTP/2, Traefik creates a connection-scoped transport holder so that an authenticated backend connection is not casually shared with another frontend client. Its HTTP/3 path reused the HTTPS handler but omitted that setup. The backend transport then fell back to a shared pool.

The difference is invisible to an ordinary browser user. The victim signs in, their request reaches the backend, and the backend connection becomes authenticated. A separate HTTP/3 client, without an Authorization header, can subsequently receive that same authenticated backend connection. The backend sees the established identity on the connection and returns data or accepts an action as the victim.

The researcher’s containerised verifier compared a working HTTP/1.1 control case, where the second client received 401, with the HTTP/3 path, where the second client read protected data and executed a simulated transfer. Its backend is synthetic, so the test establishes the connection-isolation failure without proving any particular customer’s application was breached. The reproduction validated a pinned 24 August source commit; the project advisory subsequently identified release ranges and fixes.

Which Traefik HTTP/3 deployments need action

The maintainer lists Traefik 2.11.0 through 2.11.56 and 3.0.0 through 3.7.12 as affected. Fixes are 2.11.57 and 3.7.13 respectively. Operators should confirm the running version, not just the version in a deployment file, and update the relevant branch. The advisories do not establish an affected 2.x branch outside the listed 2.11 range.

If an update cannot be deployed immediately, determine whether HTTP/3 is actually enabled on routes to a connection-bound NTLM or Negotiate backend. Disabling HTTP/3 on that entrypoint, or removing the vulnerable connection-reuse combination after application testing, can eliminate an attack precondition while a proper update is arranged. Treat this as a deployment-specific risk reduction, not a vendor-certified blanket workaround. Do not disable authentication or assume that switching a browser to HTTP/2 protects other clients while the HTTP/3 route remains reachable.

Review access logs for anomalous use of privileged endpoints and identity mismatches, but recognise the logging problem: the backend may record the victim’s authenticated identity for the stranger’s request. Correlating frontend client addresses, request identifiers and backend actions is more useful than trusting one backend username field. Investigate any sensitive action that lacks a corresponding legitimate user session.

The wider lesson is a protocol-parity failure. BlackTree has also examined how configuration determines exposure in a NetScaler authentication bypass; this case involves a different flaw and a different proxy, but likewise cannot be assessed by version alone. Traefik did not need to break NTLM itself. Its HTTP/3 code path reached the same backend while skipping the state that made earlier protocols safe for this particular authentication model. When a proxy translates between frontend protocols and connection-bound backend identity, the isolation property has to survive every route through the proxy.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *