Traefik HTTP/2 connections management could cause a denial of service
Package
Affected versions
< 2.8.8
>= 2.9.0-rc1, < 2.9.0-rc5
Patched versions
2.8.8
2.9.0-rc5
Description
Published to the GitHub Advisory Database
Oct 10, 2022
Reviewed
Oct 10, 2022
Published by the National Vulnerability Database
Oct 11, 2022
Last updated
Jul 14, 2023
Impact
There is a potential vulnerability in Traefik managing HTTP/2 connections.
A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.
Patches
Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8
Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5
Workarounds
No workaround.
For more information
If you have any questions or comments about this advisory, please open an issue.
References