StackRadar

CVE-2026-88004

High

Advisory

Published 10 Sept 2026In the index since 11 Sept 2026
Severity
High
worst across findings
CVSS
7.0
base score, highest
EPSS
0.003
21st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
6
of 17,781 indexed, latest versions
Container images
5
deployed by those charts
Fix available
1 of 1
affected package

Traefik entrypoint header-name sanitization bypassed via request trailers

Carried by container images the latest versions of 6 of 17,781 indexed charts deploy, on 5 images.

Affected packageAffected versionsFixed inImages
github.com/traefik/traefik/v3golangv3.6.12, v3.6.13, v3.7.1, v3.7.10+1 more3.7.135
OSV records
GHSA-v67p-phpq-fc8x

Charts affected

6 by stars
ChartLatestAffected imagesRadar Score
switchboardswitchboardVerified publisher0.7.41 of 1See more

switchboard switchboard 0.7.4

1 of the 1 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
ghcr.io/borchero/switchboard:0.7.454a193b757da
github.com/traefik/traefik/v3@v3.6.12
3.7.13

Open the chart page →

839
caninecanine0.1.101 of 7See more

canine canine 0.1.10

1 of the 7 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
library/traefik:v3.7.16b9cbca6fac4
github.com/traefik/traefik/v3@v3.7.1
3.7.13

Open the chart page →

14,130
traefikcanine40.2.01 of 1See more

traefik canine 40.2.0

1 of the 1 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
library/traefik:v3.7.16b9cbca6fac4
github.com/traefik/traefik/v3@v3.7.1
3.7.13

Open the chart page →

1,023
traefikcluster-deploy0.3.01 of 1See more

traefik cluster-deploy 0.3.0

1 of the 1 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
library/traefik:v3.7.109c3b91d5fb77
github.com/traefik/traefik/v3@v3.7.10
3.7.13

Open the chart page →

340
traefikgpg-dev39.0.81 of 1See more

traefik gpg-dev 39.0.8

1 of the 1 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
library/traefik:v3.6.1334d5089d0b41
github.com/traefik/traefik/v3@v3.6.13
3.7.13

Open the chart page →

1,274
traefikkubeblocksVerified publisher41.4.01 of 1See more

traefik kubeblocks 41.4.0

1 of the 1 container images this version deploys carry CVE-2026-88004.

Container imageDigestPackageFixed in
library/traefik:v3.7.129c2a54d87f76
github.com/traefik/traefik/v3@v3.7.12
3.7.13

Open the chart page →

243

Container images carrying it

5 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
library/traefik:v3.7.16b9cbca6fac4
github.com/traefik/traefik/v3@v3.7.1
3.7.13
2
library/traefik:v3.6.1334d5089d0b41
github.com/traefik/traefik/v3@v3.6.13
3.7.13
1
library/traefik:v3.7.129c2a54d87f76
github.com/traefik/traefik/v3@v3.7.12
3.7.13
1
library/traefik:v3.7.109c3b91d5fb77
github.com/traefik/traefik/v3@v3.7.10
3.7.13
1
ghcr.io/borchero/switchboard:0.7.454a193b757da
github.com/traefik/traefik/v3@v3.6.12
3.7.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.