CVE-2026-88007
CVE Details
Visit the official vulnerability details page for CVE-2026-88007 to learn more.
Initial Publication
09/10/2026
Last Update
09/14/2026
Third Party Dependency
github.com/traefik/traefik/v3
NIST CVE Summary
Traefik is an open source HTTP reverse proxy and load balancer. From 2.11.0 until 2.11.57 and 3.7.13, the HTTP/3 entrypoint ConnContext does not call service.AddTransportOnContext, so kerberosRoundTripper uses a shared backend transport instead of a transport dedicated to each frontend connection. With HTTP/3 enabled, a backend using connection-bound NTLM or Negotiate authentication, and backend keep-alive, an unrelated client can reuse a backend connection authenticated for a victim, read victim-only data, and act as that victim without the victim credentials. This issue is fixed in 2.11.57 and 3.7.13.
CVE Severity
Our Official Summary
Investigation is ongoing to determine how this vulnerability affects our products.
Status
Analyzed
Affected Products & Versions
| Version | PaletteAI | PaletteAI VerteX |
|---|---|---|
| 1.4.0 | ⚠️ Impacted | ⚠️ Impacted |
| 1.3.2 | ⚠️ Impacted | ⚠️ Impacted |
| 1.2.2 | ⚠️ Impacted | ⚠️ Impacted |
Revision History
No revisions available.