Vulnerability GO-2026-6454
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
15 days ago
September 16, 2026 at 04:56 PM UTC
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik
v1.0.0-beta.211 - v2.0.0-beta1+incompatible
v1.0.0-beta.211 - v2.0.0-beta1+incompatible
Summary
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik
Details
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded in github.com/traefik/traefik
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Unknown
7 hours ago
Traefik: BasicAuth singleflight coalescing reintroduces an unauthenticated username-enumeration timing oracle
v1.0.0-beta.211 - v2.0.0-beta1+incompatible GO-2026-6558
v1.0.0-beta.211 - v2.0.0-beta1+incompatible GO-2026-6558
Unknown
15 days ago
Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik
v3.0.0 - v3.7.11 GO-2026-6455
v3.0.0 - v3.7.11 GO-2026-6455
Unknown
15 days ago
Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik
v3.0.0 - v3.7.11 GO-2026-6455
v3.0.0 - v3.7.11 GO-2026-6455
Unknown
15 days ago
Traefik: ForwardAuth identity spoofing via dot-form header alias in github.com/traefik/traefik
v3.0.0 - v3.7.11 GO-2026-6455
v3.0.0 - v3.7.11 GO-2026-6455
Unknown
15 days ago
Traefik: Rootless HTTP/1 request-target routes as "/" but is forwarded verbatim, bypassing path-scoped routing, middleware guards and access logging in github.com/traefik/traefik
v1.0.0-beta.211 - v2.0.0-beta1+incompatible GO-2026-6465
v1.0.0-beta.211 - v2.0.0-beta1+incompatible GO-2026-6465
Impacted packages
Timeline
Published
15 days ago
September 16, 2026 at 04:56 PM UTC
Last Modified
14 days ago
September 17, 2026 at 05:40 PM UTC