Traefik 3.7.0, 3.7.11 Vulnerability: Critical CVE-2026-88877
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- traefik (github-actions)
- Affected versions
- >= v3.7.13, <= v3.7.13 or >= v3.7.12, <= v3.7.12 or >= v3.7.11, <= v3.7.11 or >= v3.7.10, <= v3.7.10 or >= v3.7.9, <= v3.7.9 or >= v3.7.8, <= v3.7.8 or >= v3.7.7, <= v3.7.7 or >= v3.7.6, <= v3.7.6 or >= v3.7.5, <= v3.7.5 or >= v3.7.4, <= v3.7.4 or >= v3.7.3, <= v3.7.3 or >= v3.7.2, <= v3.7.2 or >= v3.7.1, <= v3.7.1 or >= v3.7.0, <= v3.7.0
- Patched version
- 3.7.12
Traefik versions 3.7.0 to 3.7.11 have a critical vulnerability that allows unprotected access to backend services. Upgrade to version 3.7.12 or later to mitigate the risk.
What happened
Traefik versions 3.7.0 to 3.7.11 mishandle Kubernetes ingresses with specific annotations, leading to unprotected access to backend services. This vulnerability, tracked as CVE-2026-88877, was first flagged on September 10, 2026, and confirmed on the same day. The issue has a CVSS score of 9.8, indicating critical severity.
The vulnerability affects Traefik versions from 3.7.0 to 3.7.11 inclusive. Users of these versions should assess their exposure by checking their Traefik configurations for the affected annotations. The vulnerability has not been exploited in the wild as of the latest information.
What to do about it
- Upgrade Traefik to version 3.7.12 or later to mitigate the vulnerability.
- Review your Traefik configurations for the affected annotations and ensure they are correctly handled.
- Monitor the primary sources for any updates or additional information related to this vulnerability.
How 0Day would have caught this
traefik is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
You are affected if you are using Traefik versions 3.7.0 to 3.7.11.
What should I do right now?
Upgrade Traefik to version 3.7.12 or later.
Has this been exploited in the wild?
No, this vulnerability has not been exploited in the wild as of the latest information.