Allocation of Resources Without Limits or Throttling in Traefik - #VU145999
Published: August 27, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in the HTTP/3 request handling path when processing slow-body uploads. A remote attacker can send a slowly trickled request body to cause a denial of service.
Only deployments with HTTP/3 enabled are vulnerable.