← All CVEs NewScan detects
medium

CVE-2026-88012

Traefik respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded (CVSS 5.3)

Severity
medium
Affected product
Traefik
Affected versions
Traefik ≥ 2.8.2, < 2.11.56
Affected versions
Traefik ≥ 3.0.0, < 3.7.12
Fixed in
Traefik 2.11.56
Fixed in
Traefik 3.7.12
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-7ghq-v6jf-g56c describes the SAME defect as CVE-2026-88878 (GHSA-c9gw-2969-4fg3) with byte-identical version ranges - two ids were assigned to one Traefik fix. Written as its own row rather than folded into 88878's `cves` alone for the reason already recorded on the CVE-2026-85597 rows: an assessor keys remediation on the id, and a finding that lists only one of the two leaves the other looking unaddressed. The two rows carry each other in `cves` so the relationship survives a reader who finds only one. Do not 'clean up' the pair.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-88012 (see the 2.x row for the duplicate-id rationale).

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →