GHSA-7hj9-rv74-5g92
Traefik HTTP header parsing could cause a denial of service
Quick fix
GHSA-7hj9-rv74-5g92 — github.com/traefik/traefik/v2: upgrade to the fixed version with the command below.
go get github.com/traefik/traefik/v2@v2.9.10Details
### Impact
There is a vulnerability in [Go when parsing the HTTP headers](https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8/m/OV40vnafAwAJ), which impacts Traefik. HTTP header parsing could allocate substantially more memory than required to hold the parsed headers. This behavior could be exploited to cause a denial of service.
### References
- [CVE-2023-24534](https://www.cve.org/CVERecord?id=CVE-2023-24534)
### Patches - https://github.com/traefik/traefik/releases/tag/v2.9.10 - https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2
### Workarounds
No workaround.
### For more information
If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).
Are you affected?
Enter the version of the package you're using.
Affected packages
0Fixed in: 2.9.10go get github.com/traefik/traefik/v2@v2.9.102.10.0-rc1Fixed in: 2.10.0-rc2go get github.com/traefik/traefik/v2@v2.10.0-rc2References
- https://github.com/traefik/traefik/security/advisories/GHSA-7hj9-rv74-5g92[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2023-29013[ADVISORY]
- https://github.com/traefik/traefik/commit/4ed3964b3586565519249bbdc55eb1b961c08c49[WEB]
- https://github.com/advisories/GHSA-8v5j-pwr7-w5f8[ADVISORY]
- https://github.com/traefik/traefik[PACKAGE]
- https://github.com/traefik/traefik/releases/tag/v2.10.0-rc2[WEB]
- https://github.com/traefik/traefik/releases/tag/v2.9.10[WEB]
- https://groups.google.com/g/golang-announce/c/Xdv6JL9ENs8/m/OV40vnafAwAJ[WEB]
- https://security.netapp.com/advisory/ntap-20230517-0008[WEB]