CVE-2023-54365: Golang Go

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.

Affected products

  • Golang Go: before 1.20.10 (fixed in 1.20.10); from 1.21.0, before 1.21.3 (fixed in 1.21.3)
  • Red Hat Openshift Ai: affected versions not specified
  • Traefik Traefik: before 2.10.5 (fixed in 2.10.5); version 3.0.0 only

Published 2026-06-23. Last modified 2026-09-26.