GHSA-pvrg-q6jw-42p7High· 7.5▾ TwilightDuplicate Advisory: Traefik vulnerable to HTTP/2 request causing denial of service
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
This advisory has been withdrawn because it is a duplicate of GHSA-7v4p-328v-8v5g. This link is maintained to preserve external references.
github.com/traefik/traefik < 2.10.5Upgrade to a patched release:
github.com/traefik/traefik 2.10.5Connected by shared product, vendor, weakness, or advisory.
CVE-2023-54365High· 7.5Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' techniqu…
CVE-2026-25949High· 7.5Traefik is an HTTP reverse proxy and load balancer
CVE-2026-88012Medium· 5.3Traefik is an open source HTTP reverse proxy and load balancer
GO-2024-2941NoneACME DNS: Azure Identity Libraries Elevation of Privilege Vulnerability in github.com/traefik/traefik
GO-2024-2917NoneTraefik has unexpected behavior with IPv4-mapped IPv6 addresses in github.com/traefik/traefik
GO-2024-2880NoneTraefik vulnerable to GO issue allowing malformed DNS message to cause infinite loop in github.com/traefik/traefik