TLS Handshake Vulnerability in Traefik HTTP Reverse Proxy and Load Balancer
CVE-2026-26999
What is CVE-2026-26999?
Traefik, an HTTP reverse proxy and load balancer, contains a vulnerability related to TLS connections on TCP routers. Prior to versions 2.11.38 and 3.6.9, during the TLS handshake process, the read deadline for protocol sniffing is incorrectly cleared, leading to potential denial of service. If an attacker sends an incomplete TLS record, it can halt further communication, causing the handshake to stall indefinitely. By exploiting this weakness with multiple simultaneous connections, an attacker can exhaust server resources, ultimately impairing the availability of services routed through the affected Traefik entrypoints. The issue has been addressed in the mentioned versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
traefik < 2.11.38 < 2.11.38
traefik < 3.6.9 < 3.6.9
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
