Traefik HTTP header parsing could cause a denial of service
Package
Affected versions
< 2.9.10
= 2.10.0-rc1
Patched versions
2.9.10
2.10.0-rc2
Description
Published to the GitHub Advisory Database
Apr 11, 2023
Reviewed
Apr 11, 2023
Published by the National Vulnerability Database
Apr 14, 2023
Last updated
May 17, 2023
Impact
There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik.
HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service.
References
Patches
Workarounds
No workaround.
For more information
If you have any questions or comments about this advisory, please open an issue.
References