---
id: CVE-2024-28869
title: 'traefik: denial of service (CVE-2024-28869)'
summary: >-
  An improper handling of exceptional conditions vulnerability was found in
  Traefik. In affected versions, sending a GET request to any Traefik endpoint
  with the "Content-length" request header results in an indefinite hang with
  the default …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cvssSource: vendor
cwe: CWE-755
vendor: Red Hat
product: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23
affected:
  - openshift_dev_spaces_rhosds 3.23
patched:
  - openshift_dev_spaces_rhosds 3.23
published: '2024-04-12'
updated: '2026-09-21'
sourceUpdated: '2026-09-21T17:22:05+00:00'
source: CSAF
sourceUrl: 'https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-28869.json'
references:
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2024/cve-2024-28869.json
  - url: 'https://access.redhat.com/security/cve/CVE-2024-28869'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2274987'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2024-28869'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-28869'
  - url: >-
      https://github.com/traefik/traefik/commit/240b83b77351dfd8cadb91c305b84e9d22e0f9c6
  - url: 'https://github.com/traefik/traefik/security/advisories/GHSA-4vwx-54mw-vqfw'
  - url: 'https://access.redhat.com/errata/RHSA-2025:15847'
  - url: 'https://doc.traefik.io/traefik/routing/entrypoints/#respondingtimeouts'
  - url: 'https://github.com/traefik/traefik'
  - url: 'https://github.com/traefik/traefik/releases/tag/v2.11.2'
  - url: 'https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5'
tags:
  - csaf
  - vex
  - red-hat
  - osv
  - go
epss: 0.01046
epssPercentile: 0.62738
aliases:
  - GHSA-4vwx-54mw-vqfw
  - GO-2024-2722
ecosystem: go
ingestedAt: '2026-08-07T19:14:15.788Z'
---

## Overview

An improper handling of exceptional conditions vulnerability was found in Traefik. In affected versions, sending a GET request to any Traefik endpoint with the "Content-length" request header results in an indefinite hang with the default configuration, resulting in a denial of service.

## Vendor advisories

- **RHSA-2025:15847** · Red Hat · fixed in: Red Hat OpenShift Dev Spaces (RHOSDS) 3.23 · released 2025-09-15 · [advisory](https://access.redhat.com/errata/RHSA-2025:15847)

**traefik: denial of service** — rated Moderate by Red Hat. Released 2024-04-12, updated 2026-09-21.

Fixed:

- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23

Not affected:

- Red Hat OpenShift Dev Spaces (RHOSDS) 3.23

## Remediation

Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 https://access.redhat.com/errata/RHSA-2025:15847

## Package advisory (CVE-2024-28869)

Affected packages:

- `github.com/traefik/traefik/v3 >= 3.0.0-beta3, < 3.0.0-rc5`
- `github.com/traefik/traefik/v2 < 2.11.2`
- `github.com/traefik/traefik < 2.11.2`

Patched in:

- `github.com/traefik/traefik/v3 3.0.0-rc5`
- `github.com/traefik/traefik/v2 2.11.2`
- `github.com/traefik/traefik 2.11.2`

Source: https://osv.dev/vulnerability/GHSA-4vwx-54mw-vqfw
