Resource exhaustion in Traefik - CVE-2026-26999

 

Resource exhaustion in Traefik - CVE-2026-26999

Published: May 5, 2026


Vulnerability identifier: #VU129665
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-26999
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled resource consumption in the TCP router TLS handshake handling in (*Router).ServeTCP when processing TLS connections on TCP routers. A remote attacker can send an incomplete TLS record and stop further data transmission to cause a denial of service.

By opening many stalled connections in parallel, file descriptors and goroutines can be exhausted, degrading availability of services on the affected entrypoint.


Affected software

Traefik

How to mitigate CVE-2026-26999

Install security update from vendor's website.

Traefik - addressed in versions 2.11.38, 3.6.9

External References

Related Security Bulletins