{"data":{"id":"275a5d71-481b-47be-be6b-bb409cf592e6","title":"GHSA-7ghq-v6jf-g56c: Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded","summary":"Traefik has a vulnerability where the `readTimeout` setting (which limits how long a request can take to be fully received, including its body) doesn't work for HTTP/3 connections. This means an attacker can send a request body very slowly and keep the connection open indefinitely, wasting server resources. The bug appeared in version 2.8.2 and affects all versions from 2.8.2 through 3.6.","solution":"Upgrade to Traefik v2.11.56 or v3.7.12. These versions contain patches that restore the timeout functionality to HTTP/3 entry points.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-7ghq-v6jf-g56c","publishedAt":"2026-09-10T20:27:16.000Z","cveId":"CVE-2026-88012","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["denial_of_service"],"issueType":"vulnerability","affectedPackages":["github.com/traefik/traefik/v3@>= 3.0.0, < 3.7.12 (fixed: 3.7.12)","github.com/traefik/traefik/v2@>= 2.8.2, < 2.11.56 (fixed: 2.11.56)"],"affectedVendors":[],"affectedVendorsRaw":["Traefik"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0,"patchAvailable":true,"disclosureDate":"2026-09-10T20:27:16.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["availability"],"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}