Moderate severityOSV Advisory· Published Jan 15, 2026· Updated Jan 20, 2026
Traefik's ACME TLS-ALPN fast path lacks timeouts and close on handshake stall
CVE-2026-22045
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulnerability is fixed in 2.11.35 and 3.6.7.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
github.com/traefik/traefik/v3Go | < 3.6.7 | 3.6.7 |
github.com/traefik/traefik/v2Go | < 2.11.35 | 2.11.35 |
Affected products
8- osv-coords7 versionspkg:apk/chainguard/traefik-3.5pkg:apk/wolfi/traefik-3.5pkg:golang/github.com/traefik/traefik/v2pkg:golang/github.com/traefik/traefik/v3pkg:rpm/opensuse/govulncheck-vulndb&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/traefik2&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/traefik&distro=openSUSE%20Tumbleweed
< 3.5.6-r6+ 6 more
- (no CPE)range: < 3.5.6-r6
- (no CPE)range: < 3.5.6-r6
- (no CPE)range: < 2.11.35
- (no CPE)range: < 3.6.7
- (no CPE)range: < 0.0.20260123T022811-150000.1.140.1
- (no CPE)range: < 2.11.35-1.1
- (no CPE)range: < 3.6.7-1.1
Patches
Vulnerability mechanics
References
6- github.com/advisories/GHSA-cwjm-3f7h-9hwqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-22045ghsaADVISORY
- github.com/traefik/traefik/commit/e9f3089e9045812bcf1b410a9d40568917b26c3dghsax_refsource_MISCWEB
- github.com/traefik/traefik/releases/tag/v2.11.35ghsax_refsource_MISCWEB
- github.com/traefik/traefik/releases/tag/v3.6.7ghsax_refsource_MISCWEB
- github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwqghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.