Vulnerability record · CVE-2026-22045 · published 15 January 2026
CVE-2026-22045: Traefik allocation without limits vulnerability
Traefik · Traefik
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulnerability is fixed in 2.11.35 and 3.6.7.
Description
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.35 and 3.6.7, there is a potential vulnerability in Traefik ACME TLS certificates' automatic generation: the ACME TLS-ALPN fast path can allow unauthenticated clients to tie up go routines and file descriptors indefinitely when the ACME TLS challenge is enabled. A malicious client can open many connections, send a minimal ClientHello with acme-tls/1, then stop responding, leading to denial of service of the entry point. The vulnerability is fixed in 2.11.35 and 3.6.7.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/traefik/traefik/commit/e9f3089e9045812bcf1b410a9d40568917b26c3d | Patch |
| https://github.com/traefik/traefik/releases/tag/v2.11.35 | Release Notes |
| https://github.com/traefik/traefik/releases/tag/v3.6.7 | Release Notes |
| https://github.com/traefik/traefik/security/advisories/GHSA-cwjm-3f7h-9hwq | PatchVendor Advisory |
Track CVE-2026-22045 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2026-22045), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.