CVE-2026-25949
HIGH EPSS 45.4%
Published Feb 12, 20264mo ago · Modified Feb 20, 20264mo ago
7.5 CVSS 3.1
Published Feb 12, 2026 4mo ago
Last Modified Feb 20, 2026 4mo ago
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in 3.6.8.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector Network
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality None
Integrity None
Availability High
Threat Intelligence
EPSS Exploit Probability
45.4% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-400 Uncontrolled Resource Consumption Resource Mgmt
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| traefik | traefik | * | <3.6.8 |
References 3
- github.com https://github.com/traefik/traefik/commit/31e566e9f1d7888ccb6fbc18bfed427203c35678
- github.com https://github.com/traefik/traefik/releases/tag/v3.6.8
- github.com https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w
Remediation
- github.com https://github.com/traefik/traefik/commit/31e566e9f1d7888ccb6fbc18bfed427203c35678
- github.com https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w