ADVISORY

HIGH: github.com/traefik/traefik/v2 — Traefik: Cross-user response poisoning via proxied CONNECT on Traefik's shared backend keep-alive pool

Summary There is a critical vulnerability in Traefik's default HTTP reverse proxy that leads to unauthenticated cross-user response poisoning. When a client opens an HTTP/2 or HTTP/3 CONNECT request, Traefik forwards it — body included — to an HTTP/1.1…

Source github.com/traefik/traefik/v2Published 9d ago · Aug 6, 2026Posted on Threads

What we hold

Package
github.com/traefik/traefik/v2
Ecosystem
go
Severity
HIGH
ID
CVE-2026-71324

Summary There is a critical vulnerability in Traefik's default HTTP reverse proxy that leads to unauthenticated cross-user response poisoning. When a client opens an HTTP/2 or HTTP/3 CONNECT request, Traefik forwards it — body included — to an HTTP/1.1…

Learning about advisories like this one the day they are published is a separate problem from reading them here. Dependabot alerts, the GitHub Advisory Database API, OSV.dev and npm audit, compared against live responses: how to get an alert when a dependency has a new security advisory.