<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T06:29:57.756339+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236</id>
    <title>certfr-2026-avi-0236 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un déni de s…</title>
    <updated>2026-10-04T06:29:57.839692+00:00</updated>
    <content>certfr-2026-avi-0236</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cleanstart-2026-iz44500</id>
    <title>CLEANSTART-2026-IZ44500 — Security fix for CVE-2026-26998 applied in: forecastle 1.0.159-r1</title>
    <updated>2026-10-04T06:29:57.839737+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> CleanStart: forecastle</p>
<p>Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cleanstart-2026-iz44500"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-274806</id>
    <title>EUVD-2026-274806</title>
    <updated>2026-10-04T06:29:57.839769+00:00</updated>
    <content>EUVD-2026-274806</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-274806"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26998</id>
    <title>fkie_cve-2026-26998</title>
    <updated>2026-10-04T06:29:57.839783+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no maxResponseBodySize configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process. This results in a denial of service for all routes served by the affected Traefik instance. This issue has been patched in versions 2.11.38 and 3.6.9.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-26998"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-fw45-f5q2-2p4x</id>
    <title>GHSA-fw45-f5q2-2p4x — Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS</title>
    <updated>2026-10-04T06:29:57.839809+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3</p>
<p>## Impact</p>
<p>There is a potential vulnerability in Traefik managing the ForwardAuth middleware responses.</p>
<p>When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no `maxResponseBodySize` configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process.</p>
<p>This results in a denial of service for all routes served by the affected Traefik instance.</p>
<p>## Patches</p>
<p>- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9</p>
<p>## Workarounds</p>
<p>No workaround available.</p>
<p>## For more information</p>
<p>If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).</p>
<p>---</p>
<p>&lt;details&gt;
&lt;summary&gt;Original Description&lt;/summary&gt;</p>
<p>### Summary</p>
<p>The ForwardAuth middleware reads the entire authentication server response body into memory using io.ReadAll with no size limit. A single HTTP request through a ForwardAuth-protected route can cause the Traefik process to allocate gigabytes of memory and be killed by the OOM killer, resulting in complete denial of service for all routes on the affected entrypoint.</p>
<p>### Details</p>
<p>In pkg/middlewares/auth/forward…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-fw45-f5q2-2p4x"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1</id>
    <title>openSUSE-SU-2026:10314-1 — traefik2-2.11.40-1.1 on GA media</title>
    <updated>2026-10-04T06:29:57.839878+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>traefik2-2.11.40-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1"/>
  </entry>
</feed>
