# CVE-2026-88878

## Summary

- **CVE ID:** CVE-2026-88878
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-770
- **Published:** Sep 10, 2026
- **Last Modified:** Sep 10, 2026

## Description

Traefik is an HTTP reverse proxy and load balancer. In versions >= v2.8.2 through <= v2.11.55 and >= v3.0.0 through <= v3.7.11, the entryPoints.<name>.transport.respondingTimeouts settings — notably readTimeout, which is enabled by default at 60s — are not applied to the HTTP/3 request path. readTimeout is enforced as a deadline on the underlying TCP connection, which cannot be applied to a QUIC stream, and Traefik's HTTP/3 server is constructed without any timeout. As a result, on entry points with HTTP/3 enabled, an unauthenticated remote client that trickles request body bytes can hold a request open indefinitely and, with it, one upstream connection per request, exhausting bounded backend connection pools and causing denial of service. The issue was introduced in v2.8.2 when a quic-go API change removed the embedded http.Server that carried these timeouts. Fixed in v2.11.56 and v3.7.12.

## Affected Products

- traefik — traefik (2.8.2)
- traefik — traefik (3.0.0)

## References

- [CNA](https://github.com/traefik/traefik/security/advisories/GHSA-7ghq-v6jf-g56c)
- [CNA](https://www.vulncheck.com/advisories/traefik-2.8.2-through-3.6-http-3-timeout-bypass)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._