Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-7v4p-328v-8v5g: Traefik vulnerable to HTTP/2 request causing denial of service

Impact

A vulnerability CVE-2023-39325 exists in Go managing HTTP/2 requests, which impacts Traefik. This vulnerability could be exploited to cause a denial of service.

References

Patches

  • https://github.com/traefik/traefik/releases/tag/v2.10.5
  • https://github.com/traefik/traefik/releases/tag/v3.0.0-beta4
ghsa
#vulnerability#google#dos#git

Traefik vulnerable to HTTP/2 request causing denial of service

Moderate severity GitHub Reviewed Published Oct 12, 2023 in traefik/traefik • Updated Oct 17, 2023

ghsa: Latest News

GHSA-f27p-cmv8-xhm6: fetch: Authorization headers not dropped when redirecting cross-origin