HIGH
Traefik HTTP/2 connections management could cause a denial of service
Published Oct 11, 2022
7.5
HIGHCVSS 3.1
EPSS 1.12%
Description
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.
Affected products
-
- Version < 2.8.8StatusaffectedConstraints-
- Version >= 2.9.0-rc1, < 2.9.0-rc5StatusaffectedConstraints-
- Version
No data.
No Red Hat product state for this CVE.
github.com/traefik/traefik/v2
Go
Introduced 0 Fixed 2.8.8github.com/traefik/traefik/v2
Go
Introduced 2.9.0-rc1 Fixed 2.9.0-rc5
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| Go | github.com/traefik/traefik/v2 | 0 | 2.8.8 |
| Go | github.com/traefik/traefik/v2 | 2.9.0-rc1 | 2.9.0-rc5 |
Remediation
No remediation recorded yet.
Weaknesses (2)
References (5)
- https://github.com/advisories/GHSA-c6hx-pjc3-7fqr Advisory
- https://github.com/traefik/traefik/releases/tag/v2.8.8 Release NotesThird Party Advisory
- https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5 Release NotesThird Party Advisory
- https://github.com/traefik/traefik/security/advisories/GHSA-c6hx-pjc3-7fqr PatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-39271
| Link | Providers | Tags |
|---|---|---|
| https://github.com/advisories/GHSA-c6hx-pjc3-7fqr | Advisory | |
| https://github.com/traefik/traefik/releases/tag/v2.8.8 | Release NotesThird Party Advisory | |
| https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5 | Release NotesThird Party Advisory | |
| https://github.com/traefik/traefik/security/advisories/GHSA-c6hx-pjc3-7fqr | PatchThird Party Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-39271 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Oct 11, 2022
Updated Apr 23, 2025
Reserved Sep 2, 2022
Link CVE-2022-39271
CISA Vulnrichment
GHSA-C6HX-PJC3-7FQR Updated Apr 23, 2025