CVE-2026-88878: Traefik

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by default at 60s — are not applied to the HTTP/3 request path. readTimeout is enforced as a deadline on the underlying TCP connection, which cannot be applied to a QUIC stream, and Traefik's HTTP/3 server is constructed without any timeout. As a result, on entry points with HTTP/3 enabled, an unauthenticated remote client that trickles request body bytes can hold a request open indefinitely and, with it, one upstream connection per request, exhausting bounded backend connection pools and causing denial of service. The issue was introduced in v2.8.2 when a quic-go API change removed the embedded http.Server that carried these timeouts. Fixed in v2.11.56 and v3.7.12.

Affected products

  • Traefik Traefik: from 2.8.2, before 2.11.56 (fixed in 2.11.56); from 3.0.0, before 3.7.12 (fixed in 3.7.12)

Published 2026-09-10. Last modified 2026-10-08.