<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 08:56:37 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0236 — De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer un déni de s…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236</link>
      <description>certfr-2026-avi-0236</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0236</guid>
    </item>
    <item>
      <title>CLEANSTART-2026-IZ44500 — Security fix for CVE-2026-26998 applied in: forecastle 1.0.159-r1</title>
      <link>https://cve.radiocsirt.org/vuln/cleanstart-2026-iz44500</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: forecastle&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; CleanStart: forecastle&lt;/p&gt;
&lt;p&gt;Security vulnerability affects the forecastle package. This issue is resolved in later releases. See references for vulnerability details.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cleanstart-2026-iz44500</guid>
    </item>
    <item>
      <title>EUVD-2026-274806</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-274806</link>
      <description>EUVD-2026-274806</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-274806</guid>
    </item>
    <item>
      <title>fkie_cve-2026-26998</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-26998</link>
      <description>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no maxResponseBodySize configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process. This results in a denial of service for all routes served by the affected Traefik instance. This issue has been patched in versions 2.11.38 and 3.6.9.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.38 and 3.6.9, there is a potential vulnerability in Traefik managing the ForwardAuth middleware responses. When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no maxResponseBodySize configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process. This results in a denial of service for all routes served by the affected Traefik instance. This issue has been patched in versions 2.11.38 and 3.6.9.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-26998</guid>
    </item>
    <item>
      <title>GHSA-fw45-f5q2-2p4x — Traefik has unbounded io.ReadAll on auth server response body that causes OOM DOS</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-fw45-f5q2-2p4x</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;There is a potential vulnerability in Traefik managing the ForwardAuth middleware responses.&lt;/p&gt;
&lt;p&gt;When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no `maxResponseBodySize` configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process.&lt;/p&gt;
&lt;p&gt;This results in a denial of service for all routes served by the affected Traefik instance.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The ForwardAuth middleware reads the entire authentication server response body into memory using io.ReadAll with no size limit. A single HTTP request through a ForwardAuth-protected route can cause the Traefik process to allocate gigabytes of memory and be killed by the OOM killer, resulting in complete denial of service for all routes on the affected entrypoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In pkg/middlewares/auth/forward…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Go: github.com/traefik/traefik/v2, Go: github.com/traefik/traefik/v3&lt;/p&gt;
&lt;p&gt;## Impact&lt;/p&gt;
&lt;p&gt;There is a potential vulnerability in Traefik managing the ForwardAuth middleware responses.&lt;/p&gt;
&lt;p&gt;When Traefik is configured to use the ForwardAuth middleware, the response body from the authentication server is read entirely into memory without any size limit. There is no `maxResponseBodySize` configuration to restrict the amount of data read from the authentication server response. If the authentication server returns an unexpectedly large or unbounded response body, Traefik will allocate unlimited memory, potentially causing an out-of-memory (OOM) condition that crashes the process.&lt;/p&gt;
&lt;p&gt;This results in a denial of service for all routes served by the affected Traefik instance.&lt;/p&gt;
&lt;p&gt;## Patches&lt;/p&gt;
&lt;p&gt;- https://github.com/traefik/traefik/releases/tag/v2.11.38
- https://github.com/traefik/traefik/releases/tag/v3.6.9&lt;/p&gt;
&lt;p&gt;## Workarounds&lt;/p&gt;
&lt;p&gt;No workaround available.&lt;/p&gt;
&lt;p&gt;## For more information&lt;/p&gt;
&lt;p&gt;If there are any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).&lt;/p&gt;
&lt;p&gt;---&lt;/p&gt;
&lt;p&gt;&amp;lt;details&amp;gt;
&amp;lt;summary&amp;gt;Original Description&amp;lt;/summary&amp;gt;&lt;/p&gt;
&lt;p&gt;### Summary&lt;/p&gt;
&lt;p&gt;The ForwardAuth middleware reads the entire authentication server response body into memory using io.ReadAll with no size limit. A single HTTP request through a ForwardAuth-protected route can cause the Traefik process to allocate gigabytes of memory and be killed by the OOM killer, resulting in complete denial of service for all routes on the affected entrypoint.&lt;/p&gt;
&lt;p&gt;### Details&lt;/p&gt;
&lt;p&gt;In pkg/middlewares/auth/forward…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-fw45-f5q2-2p4x</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:10314-1 — traefik2-2.11.40-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1</link>
      <description>&lt;p&gt;traefik2-2.11.40-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;traefik2-2.11.40-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:10314-1</guid>
    </item>
  </channel>
</rss>
