CVE-2023-54365High· 7.5▾ TwilightTraefik vulnerable to HTTP/2 request causing denial of service
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
0.6% → 0.8%
Last analysed / modified upstream
— → 7.5
medium → high
A vulnerability CVE-2023-39325 exists in Go managing HTTP/2 requests, which impacts Traefik. This vulnerability could be exploited to cause a denial of service.
github.com/traefik/traefik < 2.10.5github.com/traefik/traefik >= 3.0.0-beta1, < 3.0.0-beta4Upgrade to a patched release:
github.com/traefik/traefik 2.10.5github.com/traefik/traefik 3.0.0-beta4Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-pvrg-q6jw-42p7High· 7.5Duplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service
CVE-2026-88012Medium· 5.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2020-15129Medium· 6.1Traefik vulnerable to Open Redirect via handling of X-Forwarded-Prefix header
CVE-2026-88010Medium· 6.3Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88009High· 8.2Traefik is an open source HTTP reverse proxy and load balancer
CVE-2026-88004High· 7.4Traefik is an open source HTTP reverse proxy and load balancer