Skip to content

HTTP/2 connections management could cause a deny of service

High
nmengin published GHSA-c6hx-pjc3-7fqr Oct 10, 2022

Package

No package listed

Affected versions

< 2.8.8, < 2.9.0-rc5

Patched versions

2.8.8, 2.9.0-rc5

Description

Impact

There is a potential vulnerability in Traefik managing HTTP/2 connections.
A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.

Patches

Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8
Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5

Workarounds

No workaround.

For more information

If you have any questions or comments about this advisory, please open an issue.

Severity

High

CVE ID

CVE-2022-39271

Weaknesses

No CWEs