CVE-2026-88878
Traefik respondingTimeouts (readTimeout, on by default at 60s) are not applied to the HTTP/3 request path - readTimeout is a TCP connection deadline that cannot bind a QUIC stream, so an unauthenticated client trickling body bytes holds a request and one upstream connection open indefinitely (CVSS 6.9)
- Severity
- medium
- Affected product
- Traefik
- Affected versions
- Traefik ≥ 2.8.2, < 2.11.56
- Affected versions
- Traefik ≥ 3.0.0, < 3.7.12
- Fixed in
- Traefik 2.11.56
- Fixed in
- Traefik 3.7.12
- Added to NewScan
- 2026-09-11
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
Added 2026-09-11. GHSA-c9gw-2969-4fg3, ranges from the advisory API: v2 `>= 2.8.2, < 2.11.56`, v3 `>= 3.0.0, < 3.7.12`. ge 2.8.2 is the advisory's own bound and is a REGRESSION date, not a branch floor: the quic-go API change that removed the embedded http.Server carrying these timeouts landed in 2.8.2. FIRST OF TWO medium-severity Traefik rows in this file; the pack had only critical/high before 2026-09-11, and 6.9 is medium by the CVSS bands compliance.py uses, so writing it high to match its neighbours would have inflated the rating an assessor reads.
APPLIANCE FINGERPRINT
NewScan fingerprints the Traefik appliance and reports this CVE when the detected version falls inside the affected range below.
The 3.x arm of CVE-2026-88878 (see the 2.x row). Bound is 3.7.12, not the 3.7.13 of the same day's smuggling rows.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →