Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-54365

Опубликовано: 23 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.

A flaw was found in Traefik's HTTP/2 request handling. A remote attacker can exploit this vulnerability by rapidly creating and canceling HTTP/2 streams. This can exhaust server resources, leading to a denial of service (DoS) and making the service unavailable to legitimate users. This issue is inherited from the Go standard library's HTTP/2 implementation, known as the 'Rapid Reset' technique.

Отчет

The vulnerability is not caused by Traefik-specific code. Traefik was affected because it depended on a vulnerable version of Go's HTTP/2 implementation from the golang.org/x/net module. The remediation was to update dependencies to a version containing the upstream fix.

Меры по смягчению последствий

The recommended mitigation is to upgrade Traefik to a version that includes the patched HTTP/2 dependency.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift AI (RHOAI)rhoai/odh-rhel9-operatorNot affected
Red Hat OpenShift AI (RHOAI)rhoai/rhai-cli-rhel9Not affected
Red Hat OpenShift Dev Spacesdevspaces/traefik-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2491710github.com/traefik/traefik: net/http2: Traefik: Denial of Service via HTTP/2 Rapid Reset technique

EPSS

Процентиль: 53%
0.00774
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
3 месяца назад

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.

CVSS3: 7.5
debian
3 месяца назад

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-servi ...

CVSS3: 7.5
github
3 месяца назад

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.

EPSS

Процентиль: 53%
0.00774
Низкий

7.5 High

CVSS3

Уязвимость CVE-2023-54365