CVE-2026-88878 | Traefik up to 3.0.0 HTTP/3 Server readTimeout denial of service

SecurityVulns

A vulnerability, which was classified as critical, has been found in Traefik up to 3.0.0. Affected by this vulnerability is an unknown functionality of the component HTTP/3 Server. Performing a manipulation of the argument readTimeout results in denial of service.

This vulnerability is cataloged as CVE-2026-88878. It is possible to initiate the attack remotely. There is no exploit available.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More