PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-88012 traefik CVE debrief

CVE-2026-88012 debrief based on CVE Program and NVD records. Traefik 2.8.2-2.11.55 and 3.7.11 and earlier do not apply entryPoints..transport.respondingTimeouts.readTimeout for HTTP/3 entrypoints, allowing slow request body attacks that can exhaust backend connections. This issue is fixed in 2.11.56 and 3.7.12. Affected Traefik deployments using HTTP/3 entrypoints should assess exposure, verify version upgrades, and configure timeouts to prevent attacks. The CVE record was published on 2026-09-10T16:18:08.067Z and has not been modified since then.

Vendor
traefik
Product
Unknown
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-10
Original CVE updated
2026-09-11
Advisory published
2026-09-10
Advisory updated
2026-09-11

Who should care

Traefik administrators and security teams using HTTP/3 entrypoints should assess exposure and verify version upgrades. They should also review compensating controls, monitor relevant logs, and track exceptions for exposed assets. Security teams should work with operators to ensure proper configuration of responding timeouts for HTTP/3 entrypoints and verify that deployments are not exposed to untrusted networks.

Why it matters

CVE-2026-88012 allows slow request body attacks against Traefik HTTP/3 entrypoints, potentially exhausting backend connections. Traefik administrators and security teams should assess exposure, verify version upgrades, and configure timeouts to prevent attacks.

  • Verify Traefik version and upgrade to 2.11.56 or 3.7.12 if vulnerable
  • Configure responding timeouts for HTTP/3 entrypoints to prevent slow request body attacks
  • Assess and limit exposure of Traefik deployments to untrusted networks

Technical summary

Traefik 2.8.2-2.11.55 and 3.7.11 and earlier do not apply entryPoints..transport.respondingTimeouts.readTimeout for HTTP/3 entrypoints, allowing slow request body attacks that can exhaust backend connections. This issue is fixed in 2.11.56 and 3.7.12. Affected deployments should assess exposure, verify version upgrades, and configure timeouts to prevent attacks. Reviewing HTTP/3 entrypoint settings and verifying Traefik version are crucial steps in mitigating this vulnerability. Configuring responding timeouts for HTTP/3 entrypoints can help prevent slow request body attacks.

Defensive priority

Assess exposure in Traefik deployments using HTTP/3 entrypoints, verify version upgrades, and configure timeouts

Recommended defensive actions

  • Assess Traefik deployment exposure to HTTP/3 entrypoint attacks
  • Verify and upgrade to Traefik version 2.11.56 or 3.7.12
  • Configure responding timeouts for HTTP/3 entrypoints
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

Official CVE Program and NVD records detail a Traefik vulnerability allowing slow request body attacks. The CVE record was published on 2026-09-10T16:18:08.067Z and has not been modified since then. The NVD entry is currently Undergoing Analysis. Evidence limits suggest verifying Traefik version and configuration, reviewing HTTP/3 entrypoint settings, and assessing exposure to untrusted networks.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-88012 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-88012

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-88012 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-88012

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.