VDB
GHSA-5423-jcjm-2gpv
GHSA-5423-jcjm-2gpv
PUBLISHED
CVSS 9.100000381469727 CRITICAL
Traefik affected by Go HTTP Request Smuggling Vulnerability
Risk Scores
CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| go | Go | |
| go | github.com/traefik/traefik/v2 | |
| Go | github.com/traefik/traefik/v2 | 0 |
| github.com | traefik/traefik/v3 | 3.4.0-rc1, 3.4.0-rc1, 0 |
| github.com | traefik/traefik/v3 | 0, 0, 3.4.0-rc1 |
| github.com | traefik/traefik/v2 | 0 |
| github.com | traefik/traefik/v2 | 0, 0, 0 |
| Go | net/http | |
| Go | github.com/traefik/traefik/v3 | 3.4.0-rc1, 0 |
Exploit Intelligence
- yet-another-sort-grype.html (github-poc)
- yet-another-sort-grype.html (github-poc)
- yet-another-sort-grype.html (github-poc)
- yet-another-sort-grype.html (github-poc)
- request_smuggling.go (github-poc)
- request_smuggling.go (github-poc)
- request_smuggling.go (github-poc)
- request_smuggling.go (github-poc)
- .grype.yaml (github-poc)
- .grype.yaml (github-poc)
…and 2 more exploits
Timeline
- Apr 18, 2025 CVE Published
- Mar 2, 2026 Security Advisory
References
- https://github.com/traefik/traefik/security/advisories/GHSA-5423-jcjm-2gpv url
- https://nvd.nist.gov/vuln/detail/CVE-2025-22871 advisory
- https://github.com/traefik/traefik package
- https://github.com/traefik/traefik/releases/tag/v2.11.24 url
- https://github.com/traefik/traefik/releases/tag/v3.3.6 url
- https://github.com/traefik/traefik/releases/tag/v3.4.0-rc2 url
- GitHub Advisory GHSA-5423-jcjm-2gpv vendor-advisory