MEDIUM
GHSA-7f4j-64p6-5h5v
Traefik affected by HTTP/2 CONTINUATION flood in net/http
Quick fix
GHSA-7f4j-64p6-5h5v — github.com/traefik/traefik/v2: upgrade to the fixed version with the command below.
go get github.com/traefik/traefik/v2@v2.11.2Details
There is a potential vulnerability in Traefik managing HTTP/2 connections.
More details in the [CVE-2023-45288](https://www.cve.org/CVERecord?id=CVE-2023-45288).
## Patches
- https://github.com/traefik/traefik/releases/tag/v2.11.2 - https://github.com/traefik/traefik/releases/tag/v3.0.0-rc5
## Workarounds
No workaround
## For more information
If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
Are you affected?
Enter the version of the package you're using.
Affected packages
Go/github.com/traefik/traefik/v2
Introduced in:
0Fixed in: 2.11.2Fix
go get github.com/traefik/traefik/v2@v2.11.2Go/github.com/traefik/traefik/v3
Introduced in:
3.0.0-rc1Fixed in: 3.0.0-rc5Fix
go get github.com/traefik/traefik/v3@v3.0.0-rc5