CVE-2023-29013: HTTP header parsing could cause a deny of service
Traefik (pronounced traffic) is a modern HTTP reverse proxy and load balancer for deploying microservices. There is a vulnerability in Go when parsing the HTTP headers, which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service. This issue has been patched in versions 2.9.10 and 2.10.0-rc2.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Traefik vulnerability?
The vulnerability ID for this Traefik vulnerability is CVE-2023-29013.
What is Traefik?
Traefik is a modern HTTP reverse proxy and load balancer for deploying microservices.
What is the impact of this vulnerability?
This vulnerability in Traefik can cause substantial memory allocation when parsing HTTP headers.
Which versions of Traefik are affected?
Traefik versions up to and excluding 2.9.10 are affected, as well as version 2.10.0-rc1.
How can I fix this vulnerability?
To fix this vulnerability, upgrade to Traefik version 2.10.0-rc2 or version 2.9.10.