id: GO-ID-PENDING
modules:
- module: github.com/traefik/traefik
non_go_versions:
- introduced: TODO (earliest fixed "3.6.8", vuln range "<= 3.6.7")
vulnerable_at: 1.7.34
- module: github.com/traefik/traefik/v2
vulnerable_at: 2.11.37
- module: github.com/traefik/traefik/v3
vulnerable_at: 3.6.8
summary: 'Traefik: TCP readTimeout bypass via STARTTLS on Postgres in github.com/traefik/traefik'
cves:
- CVE-2026-25949
ghsas:
- GHSA-89p3-4642-cr2w
references:
- advisory: https://github.com/advisories/GHSA-89p3-4642-cr2w
- advisory: https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w
- web: https://github.com/traefik/traefik/releases/tag/v3.6.8
source:
id: GHSA-89p3-4642-cr2w
created: 2026-02-12T16:01:20.978463495Z
review_status: UNREVIEWED
Advisory GHSA-89p3-4642-cr2w references a vulnerability in the following Go modules:
Description:
Impact
There is a potential vulnerability in Traefik managing STARTTLS requests.
An unauthenticated client can bypass Traefik entrypoint
respondingTimeouts.readTimeoutby sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service.Patches
For more information
If you have any questions or comments about this advisory, please open an issue.
Original Description...- ADVISORY: GHSA-89p3-4642-cr2w
- ADVISORY: GHSA-89p3-4642-cr2w
- WEB: https://github.com/traefik/traefik/releases/tag/v3.6.8
- github.com/traefik/traefik appears in 27 other report(s):
- data/excluded/GO-2023-2117.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7v4p-328v-8v5g #2117) DEPENDENT_VULNERABILITY
- data/reports/GO-2022-0325.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2022-23632 #325)
- data/reports/GO-2022-0808.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7h6j-2268-fhcm #808)
- data/reports/GO-2022-0923.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2021-32813, GHSA-m697-4v8f-55qg #923)
- data/reports/GO-2022-1152.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-468w-8x39-gj5v #1152)
- data/reports/GO-2022-1154.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-h2ph-vhm7-g4hp #1154)
- data/reports/GO-2023-1919.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-r3fq-cmmw-cpmm #1919)
- data/reports/GO-2023-1950.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-2cjc-rgmp-x649 #1950)
- data/reports/GO-2023-2376.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47106 #2376)
- data/reports/GO-2023-2377.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47633 #2377)
- data/reports/GO-2023-2381.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-8g85-whqh-cr2f #2381)
- data/reports/GO-2024-2722.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-4vwx-54mw-vqfw #2722)
- data/reports/GO-2024-2726.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7f4j-64p6-5h5v #2726)
- data/reports/GO-2024-2880.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-f7cq-5v43-8pwp #2880)
- data/reports/GO-2024-2917.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7jmw-8259-q9jx #2917)
- data/reports/GO-2024-2941.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-rvj4-q8q5-8grf #2941)
- data/reports/GO-2024-2973.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-39321 #2973)
- data/reports/GO-2024-3135.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-62c8-mh53-4cqv #3135)
- data/reports/GO-2024-3299.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-52003 #3299)
- data/reports/GO-2024-3342.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342)
- data/reports/GO-2025-3627.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-5423-jcjm-2gpv #3627)
- data/reports/GO-2025-3634.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2025-32431 #3634)
- data/reports/GO-2025-3719.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-vrch-868g-9jx5 #3719)
- data/reports/GO-2025-3835.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-q6gg-9f92-r9wg #3835)
- data/reports/GO-2025-4205.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7vww-mvcr-x6vj #4205)
- data/reports/GO-2025-4206.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-gm3x-23wp-hc2c #4206)
- data/reports/GO-2026-4322.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-cwjm-3f7h-9hwq #4322)
- github.com/traefik/traefik/v2 appears in 25 other report(s):
- data/excluded/GO-2022-1057.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-c6hx-pjc3-7fqr #1057) DEPENDENT_VULNERABILITY
- data/excluded/GO-2023-1715.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-7hj9-rv74-5g92 #1715) DEPENDENT_VULNERABILITY
- data/reports/GO-2022-0325.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2022-23632 #325)
- data/reports/GO-2022-0923.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2021-32813, GHSA-m697-4v8f-55qg #923)
- data/reports/GO-2022-1152.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-468w-8x39-gj5v #1152)
- data/reports/GO-2022-1154.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-h2ph-vhm7-g4hp #1154)
- data/reports/GO-2023-2376.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47106 #2376)
- data/reports/GO-2023-2377.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47633 #2377)
- data/reports/GO-2023-2381.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-8g85-whqh-cr2f #2381)
- data/reports/GO-2024-2722.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-4vwx-54mw-vqfw #2722)
- data/reports/GO-2024-2726.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7f4j-64p6-5h5v #2726)
- data/reports/GO-2024-2880.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-f7cq-5v43-8pwp #2880)
- data/reports/GO-2024-2917.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7jmw-8259-q9jx #2917)
- data/reports/GO-2024-2941.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-rvj4-q8q5-8grf #2941)
- data/reports/GO-2024-2973.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-39321 #2973)
- data/reports/GO-2024-3135.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-62c8-mh53-4cqv #3135)
- data/reports/GO-2024-3299.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-52003 #3299)
- data/reports/GO-2024-3342.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342)
- data/reports/GO-2025-3627.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-5423-jcjm-2gpv #3627)
- data/reports/GO-2025-3634.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2025-32431 #3634)
- data/reports/GO-2025-3719.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-vrch-868g-9jx5 #3719)
- data/reports/GO-2025-3835.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-q6gg-9f92-r9wg #3835)
- data/reports/GO-2025-4205.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7vww-mvcr-x6vj #4205)
- data/reports/GO-2025-4206.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-gm3x-23wp-hc2c #4206)
- data/reports/GO-2026-4322.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-cwjm-3f7h-9hwq #4322)
- github.com/traefik/traefik/v3 appears in 19 other report(s):
- data/reports/GO-2023-2376.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47106 #2376)
- data/reports/GO-2023-2377.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2023-47633 #2377)
- data/reports/GO-2023-2381.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-8g85-whqh-cr2f #2381)
- data/reports/GO-2024-2722.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-4vwx-54mw-vqfw #2722)
- data/reports/GO-2024-2726.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7f4j-64p6-5h5v #2726)
- data/reports/GO-2024-2880.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-f7cq-5v43-8pwp #2880)
- data/reports/GO-2024-2917.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-7jmw-8259-q9jx #2917)
- data/reports/GO-2024-2941.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-rvj4-q8q5-8grf #2941)
- data/reports/GO-2024-2973.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-39321 #2973)
- data/reports/GO-2024-3135.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-62c8-mh53-4cqv #3135)
- data/reports/GO-2024-3299.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2024-52003 #3299)
- data/reports/GO-2024-3342.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-hxr6-2p24-hf98 #3342)
- data/reports/GO-2025-3627.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-5423-jcjm-2gpv #3627)
- data/reports/GO-2025-3634.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: CVE-2025-32431 #3634)
- data/reports/GO-2025-3719.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-vrch-868g-9jx5 #3719)
- data/reports/GO-2025-3835.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-q6gg-9f92-r9wg #3835)
- data/reports/GO-2025-4205.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-7vww-mvcr-x6vj #4205)
- data/reports/GO-2025-4206.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik: GHSA-gm3x-23wp-hc2c #4206)
- data/reports/GO-2026-4322.yaml (x/vulndb: potential Go vuln in github.com/traefik/traefik/v2: GHSA-cwjm-3f7h-9hwq #4322)
References:
Cross references:
See doc/quickstart.md for instructions on how to triage this report.