CVE-2026-88008 is an authorization-bypass vulnerability in Traefik caused by improper handling of client-initiated HTTP/1.1 upgrades to cleartext HTTP/2 (h2c). Affected releases forward client-controlled Connection, Upgrade: h2c, and HTTP2-Settings headers to a shared backend. When that backend accepts h2c and replies with HTTP 101 Switching Protocols, Traefik establishes a raw tunnel. Subsequent HTTP/2 requests in that tunnel are not evaluated by Traefik routers or middleware, enabling access to protected paths on the same backend through an otherwise unprotected route.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This 10-file repository contains a standalone Python proof of concept for CVE-2026-88008, an h2c-upgrade tunnel vulnerability in affected Traefik releases. `poc.py` uses only Python standard-library networking primitives: it checks the protected resource over normal HTTP/1.1, sends a deliberately crafted h2c upgrade request to an unprotected route, and, after a 101 response, emits raw HTTP/2 frames to request the protected resource over the proxy-created backend tunnel. This demonstrates unauthorized access and proxy-layer middleware bypass rather than command execution or a shell payload. The repository is not part of a known exploitation framework. The `lab/` directory provides a reproducible Docker Compose environment with version-selectable Traefik, a Jetty 12 upstream configured with cleartext HTTP/2 support, static public/protected content, and Traefik routing that applies BasicAuth only to `/protected*`. The PoC supports exploit validation against vulnerable versions and a control/check mode for patched versions.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability published on August 13, 2026. The supplied CVSS vectors describe network-based exploitation without authentication or user interaction, with high confidentiality and integrity impacts. The affected product and underlying flaw are not identified. A patch publication date of September 29, 2026 is listed, and no known exploits are available.
A high-severity Traefik HTTP/2 cleartext (h2c) upgrade tunneling vulnerability that can bypass Traefik routing, authentication, IP allowlisting, rate limiting, logging, metrics, and tracing controls, enabling unauthenticated access to protected backend paths.
A high-severity Traefik HTTP/1.1 h2c-upgrade request-smuggling/authorization-bypass vulnerability. An unauthenticated attacker can use an unprotected route sharing a backend with protected routes to establish an h2c tunnel and send HTTP/2 requests directly to protected backend paths, bypassing Traefik middleware such as BasicAuth, ForwardAuth, IPAllowList, and RateLimit. Exploitation requires a backend that accepts client-initiated HTTP/1.1-to-h2c upgrades and returns HTTP 101.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.