Resource exhaustion in Traefik - CVE-2026-22045
Published: May 5, 2026
Traefik
Containous
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled resource consumption in ACME TLS-ALPN handling in pkg/server/router/tcp/router.go when processing stalled TLS-ALPN handshakes. A remote attacker can send a minimal ClientHello with acme-tls/1 and then stop responding to cause a denial of service.
Only entrypoints with the ACME TLS-ALPN challenge enabled and ACME bypass disabled are vulnerable.