There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service.
Traefik v2.8.x: https://github.com/traefik/traefik/releases/tag/v2.8.8 Traefik v2.9.x: https://github.com/traefik/traefik/releases/tag/v2.9.0-rc5
No workaround.
If you have any questions or comments about this advisory, please open an issue.
{ "severity": "HIGH", "cwe_ids": [ "CWE-400", "CWE-755" ], "nvd_published_at": "2022-10-11T14:15:00Z", "github_reviewed": true, "github_reviewed_at": "2022-10-10T21:23:30Z" }