PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25949 traefik CVE debrief

CVE-2026-25949 is a high-severity vulnerability in Traefik, an HTTP reverse proxy and load balancer. An unauthenticated client can exploit this vulnerability by sending an 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in Traefik version 3.6.8. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.5, indicating a high severity. The vulnerability was published on February 12, 2026, and last modified on June 30, 2026.

Vendor
traefik
Product
Unknown
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-02-12
Original CVE updated
2026-07-15
Advisory published
2026-02-12
Advisory updated
2026-07-15

Who should care

Administrators and users of Traefik versions prior to 3.6.8 should be aware of this vulnerability and take immediate action to upgrade to the patched version. Additionally, defenders and security teams responsible for monitoring and protecting against potential denial-of-service attacks should be aware of this vulnerability and its potential impact.

Technical summary

The vulnerability exists in Traefik's handling of STARTTLS requests. An unauthenticated client can send an 8-byte Postgres SSLRequest (STARTTLS) prelude and then stall, causing connections to remain open indefinitely. This leads to a denial of service, as the connections are not properly closed. The vulnerability is fixed in Traefik version 3.6.8, which properly handles STARTTLS requests and prevents this type of denial-of-service attack.

Defensive priority

High priority should be given to upgrading Traefik to version 3.6.8 or later. Defenders should also monitor for potential denial-of-service attacks and implement additional security measures to prevent exploitation.

Recommended defensive actions

  • Upgrade Traefik to version 3.6.8 or later
  • Monitor for potential denial-of-service attacks
  • Implement additional security measures to prevent exploitation
  • Review and update Traefik configurations to ensure proper handling of STARTTLS requests
  • Consider implementing rate limiting or other traffic management measures to prevent exploitation

Evidence notes

The vulnerability was published on February 12, 2026, and last modified on June 30, 2026. The CVSS score for this vulnerability is 7.5, indicating a high severity. The vulnerability is fixed in Traefik version 3.6.8.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25949 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25949

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25949 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25949

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/traefik/traefik/commit/31e566e9f1d7888ccb6fbc18bfed427203c35678

    [email protected] - Patch

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/traefik/traefik/releases/tag/v3.6.8

    [email protected] - Product, Release Notes

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w

    [email protected] - Patch, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:6192

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/security/cve/CVE-2026-25949

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-25949.json

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.