CVE-2023-29013High· 7.5▾ TwilightTraefik HTTP header parsing could cause a denial of service
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 12.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
1.1%
There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service.
No workaround.
If you have any questions or comments about this advisory, please open an issue.
github.com/traefik/traefik/v2 < 2.9.10github.com/traefik/traefik/v2 >= 2.10.0-rc1, < 2.10.0-rc2Upgrade to a patched release:
github.com/traefik/traefik/v2 2.9.10github.com/traefik/traefik/v2 2.10.0-rc2Connected by shared product, vendor, weakness, or advisory.
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
GHSA-f7cq-5v43-8pwpMedium· 5.3Traefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop
CVE-2023-47124Medium· 5.9Traefik vulnerable to potential DDoS via ACME HTTPChallenge