---
id: GO-2024-2726
aliases:
  - GHSA-7f4j-64p6-5h5v
title: >-
  Traefik affected by HTTP/2 CONTINUATION flood in net/http in
  github.com/traefik/traefik
summary: >-
  Traefik affected by HTTP/2 CONTINUATION flood in net/http in
  github.com/traefik/traefik
severity: none
vendor: traefik
product: github.com/traefik/traefik
ecosystem: go
affected:
  - github.com/traefik/traefik
  - github.com/traefik/traefik/v2 < 2.11.2
  - 'github.com/traefik/traefik/v3 >= 3.0.0-rc1, < 3.0.0-rc5'
patched:
  - github.com/traefik/traefik/v2 2.11.2
  - github.com/traefik/traefik/v3 3.0.0-rc5
published: '2024-06-05'
updated: '2026-08-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GO-2024-2726'
references:
  - url: 'https://github.com/traefik/traefik/security/advisories/GHSA-7f4j-64p6-5h5v'
  - url: 'https://github.com/traefik/traefik/releases/tag/v2.11.2'
  - url: 'https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5'
tags:
  - osv
  - go
ingestedAt: '2026-08-07T19:14:18.671Z'
---

## Overview

Traefik affected by HTTP/2 CONTINUATION flood in net/http in github.com/traefik/traefik

## Affected packages

- `github.com/traefik/traefik`
- `github.com/traefik/traefik/v2 < 2.11.2`
- `github.com/traefik/traefik/v3 >= 3.0.0-rc1, < 3.0.0-rc5`

## Remediation

Upgrade to a patched release:

- `github.com/traefik/traefik/v2 2.11.2`
- `github.com/traefik/traefik/v3 3.0.0-rc5`
