Name
CVE-2023-54365
Description
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
Published Date
Updated Date
Workaround
-
Advisories
https://www.vulncheck.com/advisories/traefik-denial-of-service-via-http-2-request-handlingThird Party Advisory
https://access.redhat.com/security/cve/CVE-2023-54365Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2491710Third Party Advisory
https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-54365.jsonThird Party Advisory
Analysis#
Vulnerability Ratings#
8.7
CVSSv4
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components#
Name
Project
Project Version
Version
Status
openwrt
master
1.24.13-r1
Not Affected
openwrt
master
1.27.0-r1
Not Affected
openwrt
openwrt-25.12
1.24.13-r1
Not Affected
openwrt
openwrt-25.12
1.26.6-r1
Not Affected
yocto
master
1.26.6
Not Affected
yocto
master
1.26.6
Not Affected
yocto
scarthgap
1.22.12
Not Affected
yocto
scarthgap
1.22.12
Not Affected