CVE-2023-47124Medium· 5.9▾ SunlitTraefik vulnerable to potential DDoS via ACME HTTPChallenge
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.8%
There is a potential vulnerability in Traefik managing the ACME HTTP challenge.
When Traefik is configured to use the HTTPChallenge to generate and renew the Let's Encrypt TLS certificates, the delay authorized to solve the challenge (50 seconds) can be exploited by attackers (slowloris attack).
Replace the HTTPChallenge with the TLSChallenge or the DNSChallenge.
If you have any questions or comments about this advisory, please open an issue.
github.com/traefik/traefik/v2 < 2.10.6github.com/traefik/traefik/v3 < 3.0.0-beta5Upgrade to a patched release:
github.com/traefik/traefik/v2 2.10.6github.com/traefik/traefik/v3 3.0.0-beta5Connected by shared product, vendor, weakness, or advisory.
CVE-2023-47106Medium· 6.5Traefik incorrectly processes fragment in the URL, leads to Authorization Bypass
CVE-2023-47633High· 7.5Traefik docker container using 100% CPU
CVE-2023-29013High· 7.5Traefik HTTP header parsing could cause a denial of service
GHSA-46wh-3698-f2cxHighTraefik: Deny Rule Bypass via Unauthenticated Malicious gRPC Requests in gRPC-Go Dependency (CVE-2026-33186)
CVE-2026-41181MediumTraefik's errors middleware forwards Authorization and Cookie headers to separate error page service
CVE-2022-23469Low· 3.5Traefik may display authorization header in the debug logs