Allocation of Resources Without Limits or Throttling in Traefik - CVE-2026-26998

 

Allocation of Resources Without Limits or Throttling in Traefik - CVE-2026-26998

Published: May 5, 2026


Vulnerability identifier: #VU129664
CSH Severity: Low
CVSS v4: 5.9 [CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26998
CWE-ID: CWE-770
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in the ForwardAuth middleware when processing responses from the configured authentication server. A remote privileged user can send a request through a ForwardAuth-protected route to cause a denial of service.

Exploitation requires Traefik to be configured to use the ForwardAuth middleware, and the authentication server must return an unexpectedly large or unbounded response body.


Affected software

Traefik

How to mitigate CVE-2026-26998

Install security update from vendor's website.

Traefik - addressed in versions 2.11.38, 3.6.9

External References

Related Security Bulletins