Skip to content

x/vulndb: potential Go vuln in github.com/traefik/traefik/v3: GHSA-89p3-4642-cr2w #4484

Description

@GoVulnBot

Advisory GHSA-89p3-4642-cr2w references a vulnerability in the following Go modules:

Module
github.com/traefik/traefik
github.com/traefik/traefik/v2
github.com/traefik/traefik/v3

Description:

Impact

There is a potential vulnerability in Traefik managing STARTTLS requests.

An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service.

Patches

For more information

If you have any questions or comments about this advisory, please open an issue.

Original Description...

References:

Cross references:

See doc/quickstart.md for instructions on how to triage this report.

id: GO-ID-PENDING
modules:
    - module: github.com/traefik/traefik
      non_go_versions:
        - introduced: TODO (earliest fixed "3.6.8", vuln range "<= 3.6.7")
      vulnerable_at: 1.7.34
    - module: github.com/traefik/traefik/v2
      vulnerable_at: 2.11.37
    - module: github.com/traefik/traefik/v3
      vulnerable_at: 3.6.8
summary: 'Traefik: TCP readTimeout bypass via STARTTLS on Postgres in github.com/traefik/traefik'
cves:
    - CVE-2026-25949
ghsas:
    - GHSA-89p3-4642-cr2w
references:
    - advisory: https://github.com/advisories/GHSA-89p3-4642-cr2w
    - advisory: https://github.com/traefik/traefik/security/advisories/GHSA-89p3-4642-cr2w
    - web: https://github.com/traefik/traefik/releases/tag/v3.6.8
source:
    id: GHSA-89p3-4642-cr2w
    created: 2026-02-12T16:01:20.978463495Z
review_status: UNREVIEWED

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions