CVE-2023-54365

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:3.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:3.0.0:beta2:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:3.0.0:beta3:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*

Configuration 3 (hide)

cpe:2.3:a:redhat:openshift_ai:-:*:*:*:*:*:*:*

History

08 Jul 2026, 18:12

Type Values Removed Values Added
References () https://github.com/traefik/traefik/security/advisories/GHSA-7v4p-328v-8v5g - () https://github.com/traefik/traefik/security/advisories/GHSA-7v4p-328v-8v5g - Patch, Vendor Advisory
References () https://www.vulncheck.com/advisories/traefik-denial-of-service-via-http-2-request-handling - () https://www.vulncheck.com/advisories/traefik-denial-of-service-via-http-2-request-handling - Third Party Advisory
References () https://access.redhat.com/security/cve/CVE-2023-54365 - () https://access.redhat.com/security/cve/CVE-2023-54365 - Third Party Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2491710 - () https://bugzilla.redhat.com/show_bug.cgi?id=2491710 - Third Party Advisory
References () https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-54365.json - () https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-54365.json - Third Party Advisory
CPE cpe:2.3:a:traefik:traefik:3.0.0:beta3:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_ai:-:*:*:*:*:*:*:*
cpe:2.3:a:golang:go:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:3.0.0:beta1:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:3.0.0:beta2:*:*:*:*:*:*
First Time Traefik
Golang
Golang go
Redhat openshift Ai
Redhat
Traefik traefik

30 Jun 2026, 03:16

Type Values Removed Values Added
CWE CWE-770
References
  • () https://access.redhat.com/security/cve/CVE-2023-54365 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2491710 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2023/cve-2023-54365.json -

23 Jun 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 13:16

Updated : 2026-07-15 02:17


NVD link : CVE-2023-54365

Mitre link : CVE-2023-54365

CVE.ORG link : CVE-2023-54365


JSON object : View

Products Affected

golang

  • go

traefik

  • traefik

redhat

  • openshift_ai
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling