VDB
KO

GO-2024-2722

Traefik vulnerable to denial of service with Content-length header in github.com/traefik/traefik

Quick fix

GO-2024-2722 — github.com/traefik/traefik/v2: upgrade to the fixed version with the command below.

go get github.com/traefik/traefik/v2@v2.11.2

Details

Traefik vulnerable to denial of service with Content-length header in github.com/traefik/traefik

Are you affected?

Enter the version of the package you're using.

Affected packages

Go / github.com/traefik/traefik
Introduced in: 0

No fixed version published yet for github.com/traefik/traefik (go modules). Pin to a known-safe version or switch to an alternative.

Go / github.com/traefik/traefik/v2
Introduced in: 0 Fixed in: 2.11.2
Fix go get github.com/traefik/traefik/v2@v2.11.2
Go / github.com/traefik/traefik/v3
Introduced in: 3.0.0-beta3 Fixed in: 3.0.0-rc5
Fix go get github.com/traefik/traefik/v3@v3.0.0-rc5

References