Answer in brief
CVE-2026-88012 records a Medium severity (CVSS 6.9) vulnerability in Traefik v2.8.2 through v3.6 HTTP/3 Timeout Bypass. The current sources do not mark it as known exploited. The current feed maps traefik/traefik (generic), traefik/traefik (generic), traefik/traefik (generic), traefik/traefik (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.9. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps traefik/traefik (generic), traefik/traefik (generic), traefik/traefik (generic), traefik/traefik (generic) and additional mapped packages. Check affected ranges and fixed versions before updating.
| Product | Affected versions | Fixed versions |
|---|---|---|
| cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | Not reported | Not reported |
| Package | Affected range | Fixed version |
|---|---|---|
| traefik/traefikgeneric | >=2.8.2 <2.11.56 || >=3.0.0 <3.7.12 | 2.11.56, 3.7.12 |
| traefik/traefikgeneric | >=2.8.2 <=3.7.13 | Not reported |
| traefik/traefikgeneric | >=3.0.0 <=3.7.13 | Not reported |
| traefik/traefikgeneric | 2.8.2 | Not reported |
| traefik/traefikgeneric | 3.0.0 | Not reported |
| github.com/traefik/traefikgo | >=0 | Not reported |
| github.com/traefik/traefik/v2go | >=2.8.2,<2.11.56 | 2.11.56 |
| github.com/traefik/traefik/v2go | >=2.8.2 <2.11.56 | 2.11.56 |
| github.com/traefik/traefik/v3go | >=3.0.0,<3.7.12 | 3.7.12 |
| github.com/traefik/traefik/v3go | >=3.0.0 <3.7.12 | 3.7.12 |
Published upstream
Sep 10, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 10, 2026
Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by default at 60s — are not applied to the HTTP/3 request path. readTimeout is enforced as a deadline on the underlying TCP connection, which cannot be applied to a QUIC stream, and Traefik's HTTP/3 server is constructed without any timeout. As a result, on entry points with HTTP/3 enabled, an unauthenticated remote client that trickles request body bytes can hold a request open indefinitely and, with it, one upstream connection per request, exhausting bounded backend connection pools and causing denial of service. The issue was introduced in v2.8.2 when a quic-go API change removed the embedded http.Server that carried these timeouts. Fixed in v2.11.56 and v3.7.12.
Quoted source text, attributed separately from HOL analysis.