-
Notifications
You must be signed in to change notification settings - Fork 75
Open
Labels
Description
Advisory GHSA-cwjm-3f7h-9hwq references a vulnerability in the following Go modules:
| Module |
|---|
| github.com/traefik/traefik |
| github.com/traefik/traefik/v2 |
Description:
Impact
There is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up goroutines and file descriptors indefinitely when the ACME TLS challenge is enabled.
A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entrypoint.
Patches
- https://github.com/traefik/traefik/releases/tag/v2.11.35
- https://github.com/traefik/traefik/releases/tag/v3.6.7
For more information
If you have any quest...
References:
- ADVISORY: GHSA-cwjm-3f7h-9hwq
- ADVISORY: GHSA-cwjm-3f7h-9hwq
- FIX: traefik/traefik@e9f3089
- WEB: https://github.com/traefik/traefik/releases/tag/v2.11.35
- WEB: https://github.com/traefik/traefik/releases/tag/v3.6.7
Cross references:
- github.com/traefik/traefik appears in 26 other report(s):
- data/excluded/GO-2023-2117.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7v4p-328v-8v5g #2117) DEPENDENT_VULNERABILITY
- data/reports/GO-2022-0325.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2022-23632 #325)
- data/reports/GO-2022-0808.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7h6j-2268-fhcm #808)
- data/reports/GO-2022-0923.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2021-32813, GHSA-m697-4v8f-55qg #923)
- data/reports/GO-2022-1152.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-468w-8x39-gj5v #1152)
- data/reports/GO-2022-1154.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-h2ph-vhm7-g4hp #1154)
- data/reports/GO-2023-1919.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-r3fq-cmmw-cpmm #1919)
- data/reports/GO-2023-1950.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-2cjc-rgmp-x649 #1950)
- data/reports/GO-2023-2376.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47106 #2376)
- data/reports/GO-2023-2377.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47633 #2377)
- data/reports/GO-2023-2381.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-8g85-whqh-cr2f #2381)
- data/reports/GO-2024-2722.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-4vwx-54mw-vqfw #2722)
- data/reports/GO-2024-2726.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7f4j-64p6-5h5v #2726)
- data/reports/GO-2024-2880.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-f7cq-5v43-8pwp #2880)
- data/reports/GO-2024-2917.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7jmw-8259-q9jx #2917)
- data/reports/GO-2024-2941.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-rvj4-q8q5-8grf #2941)
- data/reports/GO-2024-2973.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-39321 #2973)
- data/reports/GO-2024-3135.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-62c8-mh53-4cqv #3135)
- data/reports/GO-2024-3299.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-52003 #3299)
- data/reports/GO-2024-3342.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342)
- data/reports/GO-2025-3627.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-5423-jcjm-2gpv #3627)
- data/reports/GO-2025-3634.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2025-32431 #3634)
- data/reports/GO-2025-3719.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-vrch-868g-9jx5 #3719)
- data/reports/GO-2025-3835.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-q6gg-9f92-r9wg #3835)
- data/reports/GO-2025-4205.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7vww-mvcr-x6vj #4205)
- data/reports/GO-2025-4206.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-gm3x-23wp-hc2c #4206)
- github.com/traefik/traefik/v2 appears in 24 other report(s):
- data/excluded/GO-2022-1057.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-c6hx-pjc3-7fqr #1057) DEPENDENT_VULNERABILITY
- data/excluded/GO-2023-1715.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-7hj9-rv74-5g92 #1715) DEPENDENT_VULNERABILITY
- data/reports/GO-2022-0325.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2022-23632 #325)
- data/reports/GO-2022-0923.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2021-32813, GHSA-m697-4v8f-55qg #923)
- data/reports/GO-2022-1152.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-468w-8x39-gj5v #1152)
- data/reports/GO-2022-1154.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-h2ph-vhm7-g4hp #1154)
- data/reports/GO-2023-2376.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47106 #2376)
- data/reports/GO-2023-2377.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47633 #2377)
- data/reports/GO-2023-2381.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-8g85-whqh-cr2f #2381)
- data/reports/GO-2024-2722.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-4vwx-54mw-vqfw #2722)
- data/reports/GO-2024-2726.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7f4j-64p6-5h5v #2726)
- data/reports/GO-2024-2880.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-f7cq-5v43-8pwp #2880)
- data/reports/GO-2024-2917.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7jmw-8259-q9jx #2917)
- data/reports/GO-2024-2941.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-rvj4-q8q5-8grf #2941)
- data/reports/GO-2024-2973.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-39321 #2973)
- data/reports/GO-2024-3135.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-62c8-mh53-4cqv #3135)
- data/reports/GO-2024-3299.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-52003 #3299)
- data/reports/GO-2024-3342.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342)
- data/reports/GO-2025-3627.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-5423-jcjm-2gpv #3627)
- data/reports/GO-2025-3634.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2025-32431 #3634)
- data/reports/GO-2025-3719.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-vrch-868g-9jx5 #3719)
- data/reports/GO-2025-3835.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-q6gg-9f92-r9wg #3835)
- data/reports/GO-2025-4205.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7vww-mvcr-x6vj #4205)
- data/reports/GO-2025-4206.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-gm3x-23wp-hc2c #4206)
See doc/quickstart.md for instructions on how to triage this report.
id: GO-ID-PENDING
modules:
- module: github.com/traefik/traefik
non_go_versions:
- introduced: TODO (earliest fixed "2.11.35", vuln range "<= 2.11.34")
- introduced: TODO (earliest fixed "3.6.7", vuln range "<= 3.6.6")
vulnerable_at: 1.7.34
- module: github.com/traefik/traefik/v2
vulnerable_at: 2.11.35
summary: Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall in github.com/traefik/traefik
cves:
- CVE-2026-22045
ghsas:
- GHSA-cwjm-3f7h-9hwq
references:
- advisory: https://github.com/advisories/GHSA-cwjm-3f7h-9hwq
- advisory: https://github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwq
- fix: https://github.com/traefik/traefik/commit/e9f3089e9045812bcf1b410a9d40568917b26c3d
- web: https://github.com/traefik/traefik/releases/tag/v2.11.35
- web: https://github.com/traefik/traefik/releases/tag/v3.6.7
source:
id: GHSA-cwjm-3f7h-9hwq
created: 2026-01-15T23:01:21.962901777Z
review_status: UNREVIEWED