Database/Container, Kubernetes & orchestration
Traefik: GET with a Content-Length header hangs the endpoint indefinitely
CVSS 7.5CVE-2024-28869Container, Kubernetes & orchestrationcurated
Impact
GET with a Content-Length header hangs the endpoint indefinitely; ingress DoS
Who can reach it
Unauthenticated network
What to do
Rolling Traefik upgrade
References
Related entries
- Traefik: IP allow-lists bypassed via HTTP/3 early data in QUIC 0-RTT with spoofed addressesCVE-2024-39321 · TraefikHigh
- Traefik: Path traversal in the WASM plugin installation mechanismCVE-2025-54386 · TraefikHigh
- Traefik: A tenant with HTTPRoute creation rights exposes the REST provider handler, bypassing provider isolationCVE-2026-44774 · TraefikMedium
- Traefik: A tenant with HTTPRoute write access injects backtick-delimited rule tokens into Traefik's routerCVE-2026-29777 · TraefikMedium
- Traefik: Cross-namespace isolation not enforced in the Kubernetes CRD providerCVE-2026-41174 · TraefikMedium
- Traefik: Traefik-added X-Forwarded-* headers can be spoofed by the client and are trusted by the backendCVE-2024-45410 · TraefikCritical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.