HTTP/3 Entry Point Vulnerability in Traefik Load Balancer
CVE-2026-88012
5.3MEDIUM
What is CVE-2026-88012?
An issue was identified in the Traefik load balancer versions preceding 2.11.56 and 3.7.12, where HTTP/3 entrypoints fail to enforce timeout settings due to the lack of a corresponding QUIC stream deadline. This flaw allows unauthenticated clients to exploit slow request bodies by sending data at a trickle, effectively holding connections open indefinitely. This can lead to exhaustion of backend resources within bounded connection pools, compromising application performance and availability. The vulnerability has been addressed in the fixed versions 2.11.56 and 3.7.12.
Affected Version(s)
traefik >= 2.8.2, < 2.11.56 < 2.8.2, 2.11.56
traefik >= 3.0.0, < 3.7.12 < 3.0.0, 3.7.12
