CVE-2026-22045

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulnerability is fixed in 2.11.35 and 3.6.7.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*

History

23 Jan 2026, 19:29

Type Values Removed Values Added
CPE cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
First Time Traefik
Traefik traefik
References () https://github.com/traefik/traefik/commit/e9f3089e9045812bcf1b410a9d40568917b26c3d - () https://github.com/traefik/traefik/commit/e9f3089e9045812bcf1b410a9d40568917b26c3d - Patch
References () https://github.com/traefik/traefik/releases/tag/v2.11.35 - () https://github.com/traefik/traefik/releases/tag/v2.11.35 - Release Notes
References () https://github.com/traefik/traefik/releases/tag/v3.6.7 - () https://github.com/traefik/traefik/releases/tag/v3.6.7 - Release Notes
References () https://github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwq - () https://github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwq - Patch, Vendor Advisory

15 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-15 23:15

Updated : 2026-01-23 19:29


NVD link : CVE-2026-22045

Mitre link : CVE-2026-22045

CVE.ORG link : CVE-2026-22045


JSON object : View

Products Affected

traefik

  • traefik
CWE
CWE-770

Allocation of Resources Without Limits or Throttling