← All CVEs NewScan detects
medium

CVE-2026-88878

Traefik respondingTimeouts (readTimeout, on by default at 60s) are not applied to the HTTP/3 request path - readTimeout is a TCP connection deadline that cannot bind a QUIC stream, so an unauthenticated client trickling body bytes holds a request and one upstream connection open indefinitely (CVSS 6.9)

Severity
medium
Affected product
Traefik
Affected versions
Traefik ≥ 2.8.2, < 2.11.56
Affected versions
Traefik ≥ 3.0.0, < 3.7.12
Fixed in
Traefik 2.11.56
Fixed in
Traefik 3.7.12
Added to NewScan
2026-09-11
Detected by
NewScan — free, self-hosted

How NewScan reports it

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

Added 2026-09-11. GHSA-c9gw-2969-4fg3, ranges from the advisory API: v2 `>= 2.8.2, < 2.11.56`, v3 `>= 3.0.0, < 3.7.12`. ge 2.8.2 is the advisory's own bound and is a REGRESSION date, not a branch floor: the quic-go API change that removed the embedded http.Server carrying these timeouts landed in 2.8.2. FIRST OF TWO medium-severity Traefik rows in this file; the pack had only critical/high before 2026-09-11, and 6.9 is medium by the CVSS bands compliance.py uses, so writing it high to match its neighbours would have inflated the rating an assessor reads.

APPLIANCE FINGERPRINT

NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.

The 3.x arm of CVE-2026-88878 (see the 2.x row). Bound is 3.7.12, not the 3.7.13 of the same day's smuggling rows.

References

Scan for this yourself — local, in-band scanning is free.

Get NewScan (FREE) →