Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
Metrics
Affected Vendors & Products
References
History
Tue, 23 Jun 2026 12:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability. | |
| Title | Traefik - Denial of Service via HTTP/2 Request Handling | |
| First Time appeared |
Traefik
Traefik traefik Enterprise |
|
| Weaknesses | CWE-400 | |
| CPEs | cpe:2.3:a:traefik:traefik_enterprise:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Traefik
Traefik traefik Enterprise |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-06-23T12:12:51.853Z
Reserved: 2026-06-22T21:54:30.246Z
Link: CVE-2023-54365
No data.
No data.
No data.
OpenCVE Enrichment
No data.