CVE-2023-54365
Awaiting Analysis Awaiting Analysis - Queue
HTTP/2 Rapid Reset DoS in Traefik

Publication date: 2026-06-23

Last updated on: 2026-06-23

Assigner: VulnCheck

Description
Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard library's HTTP/2 implementation (CVE-2023-44487 / CVE-2023-39325, the 'Rapid Reset' technique). A remote attacker can rapidly create and cancel HTTP/2 streams to exhaust server resources and cause service unavailability.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-23
Last Modified
2026-06-23
Generated
2026-06-23
AI Q&A
2026-06-23
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
traefik traefik to 3.0.0-beta4 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2023-54365 is a denial-of-service (DoS) vulnerability affecting Traefik, a popular reverse proxy and load balancer. It stems from the Go programming language's HTTP/2 request handling implementation. Specifically, the vulnerability allows a remote attacker to rapidly create and cancel HTTP/2 streams using the 'Rapid Reset' technique, which exhausts server resources.

This issue affects Traefik versions before 2.10.5 and 3.0.0-beta4, as well as certain Go versions. There are no known workarounds, and the recommended mitigation is to upgrade to the patched versions.

Impact Analysis

This vulnerability can be exploited by a remote attacker to cause a denial of service on affected Traefik servers. By rapidly creating and canceling HTTP/2 streams, the attacker can exhaust server resources, leading to service unavailability.

The impact is a disruption of normal service operations, potentially causing downtime and affecting the availability of applications or services relying on Traefik.

Mitigation Strategies

To mitigate this vulnerability, you should upgrade Traefik to the patched versions that address this issue.

  • Upgrade Traefik to version 2.10.5 or later.
  • If using beta versions, upgrade to Traefik 3.0.0-beta4 or later.

There are no known workarounds for this vulnerability, so upgrading is the recommended immediate action.

Compliance Impact

The provided information does not specify any direct impact of this vulnerability on compliance with common standards and regulations such as GDPR or HIPAA.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54365. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart