CVE-2026-25949

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in 3.6.8.
Configurations

Configuration 1 (hide)

cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*

History

20 Feb 2026, 18:44

Type Values Removed Values Added
CPE cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
Summary
  • (es) Traefik es un proxy inverso HTTP y un balanceador de carga. Antes de la versión 3.6.8, existe una posible vulnerabilidad en Traefik al gestionar solicitudes STARTTLS. Un cliente no autenticado puede eludir el respondingTimeouts.readTimeout del punto de entrada de Traefik enviando el preámbulo de 8 bytes de Postgres SSLRequest (STARTTLS) y luego estancándose, lo que provoca que las conexiones permanezcan abiertas indefinidamente, lo que lleva a una denegación de servicio. Esta vulnerabilidad se corrige en la versión 3.6.8.
References () https://github.com/traefik/traefik/commit/31e566e9f1d7888ccb6fbc18bfed427203c35678 - () https://github.com/traefik/traefik/commit/31e566e9f1d7888ccb6fbc18bfed427203c35678 - Patch
References () https://github.com/traefik/traefik/releases/tag/v3.6.8 - () https://github.com/traefik/traefik/releases/tag/v3.6.8 - Product, Release Notes
References () https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w - () https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w - Patch, Vendor Advisory
First Time Traefik
Traefik traefik

12 Feb 2026, 20:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-12 20:16

Updated : 2026-02-20 18:44


NVD link : CVE-2026-25949

Mitre link : CVE-2026-25949

CVE.ORG link : CVE-2026-25949


JSON object : View

Products Affected

traefik

  • traefik
CWE
CWE-400

Uncontrolled Resource Consumption