GITHUB-ACTIONS · SEPTEMBER 2026 · CONFIRMED

Traefik 3.7.0, 3.7.11 Vulnerability: Critical CVE-2026-88877

Severity
CRITICAL
CVSS
9.8
Affected component
traefik (github-actions)
Affected versions
>= v3.7.13, <= v3.7.13 or >= v3.7.12, <= v3.7.12 or >= v3.7.11, <= v3.7.11 or >= v3.7.10, <= v3.7.10 or >= v3.7.9, <= v3.7.9 or >= v3.7.8, <= v3.7.8 or >= v3.7.7, <= v3.7.7 or >= v3.7.6, <= v3.7.6 or >= v3.7.5, <= v3.7.5 or >= v3.7.4, <= v3.7.4 or >= v3.7.3, <= v3.7.3 or >= v3.7.2, <= v3.7.2 or >= v3.7.1, <= v3.7.1 or >= v3.7.0, <= v3.7.0
Patched version
3.7.12
CVE-2026-88877

Traefik versions 3.7.0 to 3.7.11 have a critical vulnerability that allows unprotected access to backend services. Upgrade to version 3.7.12 or later to mitigate the risk.

What happened

Traefik versions 3.7.0 to 3.7.11 mishandle Kubernetes ingresses with specific annotations, leading to unprotected access to backend services. This vulnerability, tracked as CVE-2026-88877, was first flagged on September 10, 2026, and confirmed on the same day. The issue has a CVSS score of 9.8, indicating critical severity.

The vulnerability affects Traefik versions from 3.7.0 to 3.7.11 inclusive. Users of these versions should assess their exposure by checking their Traefik configurations for the affected annotations. The vulnerability has not been exploited in the wild as of the latest information.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If traefik is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

You are affected if you are using Traefik versions 3.7.0 to 3.7.11.

What should I do right now?

Upgrade Traefik to version 3.7.12 or later.

Has this been exploited in the wild?

No, this vulnerability has not been exploited in the wild as of the latest information.

Sources

Join the 0Day waitlist →

← Back to all threats