SB2026050530 - Resource exhaustion in Traefik
Published: May 5, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Resource exhaustion (CVE-ID: CVE-2026-22045)
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in ACME TLS-ALPN handling in pkg/server/router/tcp/router.go when processing stalled TLS-ALPN handshakes. A remote attacker can send a minimal ClientHello with acme-tls/1 and then stop responding to cause a denial of service.
Only entrypoints with the ACME TLS-ALPN challenge enabled and ACME bypass disabled are vulnerable.
Remediation
Install update from vendor's website.