CVE-2026-88012
Traefik respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded (CVSS 5.3)
- Severity
- medium
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.8.2, < 2.11.56
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.12
- Fixed in
- Traefik 2.11.56
- Fixed in
- Traefik 3.7.12
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-7ghq-v6jf-g56c describes the SAME defect as CVE-2026-88878 (GHSA-c9gw-2969-4fg3) with byte-identical version ranges - two ids were assigned to one Traefik fix. Written as its own row rather than folded into 88878's `cves` alone for the reason already recorded on the CVE-2026-85597 rows: an assessor keys remediation on the id, and a finding that lists only one of the two leaves the other looking unaddressed. The two rows carry each other in `cves` so the relationship survives a reader who finds only one. Do not 'clean up' the pair.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-88012 (see the 2.x row for the duplicate-id rationale).
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →