GHSA-7v4p-328v-8v5gHighCVSS 7.5

Traefik vulnerable to HTTP/2 request causing denial of service

Published
October 17, 2023
Last Modified
September 22, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

A vulnerability CVE-2023-39325 exists in Go managing HTTP/2 requests, which impacts Traefik. This vulnerability could be exploited to cause a denial of service.

References

Patches

  • https://github.com/traefik/traefik/releases/tag/v2.10.5
  • https://github.com/traefik/traefik/releases/tag/v3.0.0-beta4

🎯 Affected products2

  • go/github.com/traefik/traefik:< 2.10.5
  • go/github.com/traefik/traefik:>= 3.0.0-beta1, < 3.0.0-beta4

🔗 References (8)