PT-2026-51489 · Traefik · Traefik
CVE-2023-54365
·
Published
2023-10-17
·
Updated
2026-07-09
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Traefik versions prior to 2.10.5
Description
A flaw exists in the HTTP/2 request handling, inherited from the Go standard library implementation. A remote attacker can trigger a denial of service (DoS) by rapidly creating and canceling HTTP/2 streams, a method known as the Rapid Reset technique, which exhausts server resources and makes the service unavailable to legitimate users.
Recommendations
Update to version 2.10.5 or later.
Exploit
Fix
DoS
Resource Exhaustion
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Traefik