cvedb.io
CVE-2022-39271
HIGH · CVSS 7.5
EPSS exploitation probability: 0%
Published 2022-10-11T14:15:09.883 · Last modified 2026-06-17T04:58:02.643

Summary

Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer that assists in deploying microservices. There is a potential vulnerability in Traefik managing HTTP/2 connections. A closing HTTP/2 server connection could hang forever because of a subsequent fatal error. This failure mode could be exploited to cause a denial of service. There has been a patch released in versions 2.8.8 and 2.9.0-rc5. There are currently no known workarounds.

Affected products

traefik — traefik

Does this affect you?

Add your gear to cvedb and we'll alert you only when traefik ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.