Description

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in 3.6.8.

INFO

Published Date :

2026-02-12T20:01:19.600Z

Last Modified :

2026-02-12T21:16:17.659Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-25949 vulnerability.

Vendors Products
Traefik
  • Traefik

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact