By vendor
Golang vulnerabilities
Known CVEs affecting Golang products, prioritized by severity, with SEC.co remediation and detection guidance.
1 published vulnerability
- CVE-2023-54365HIGH 7.5
Traefik, a widely-used API gateway and reverse proxy, is vulnerable to a denial-of-service attack that allows remote attackers to disable the service without authentication. The vulnerability stems from how Traefik handles HTTP/2 connections—attackers can rapidly open and close streams to overwhelm server resources. This flaw was inherited from Go's standard HTTP/2 library and affects Traefik versions before 2.10.5 and 3.0.0-beta4. No special privileges or interaction is required; an attacker on the network can trigger the issue simply by sending crafted HTTP/2 requests.