Bug 2444876 (CVE-2026-26998)
| Summary: | CVE-2026-26998 github.com/traefik/traefik: Traefik: Denial of Service due to unbounded ForwardAuth middleware response processing | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | CC: | sdawley |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Traefik, an HTTP reverse proxy and load balancer. When Traefik is configured to use the ForwardAuth middleware, it reads the authentication server's response body into memory without a size limit. A malicious or misconfigured authentication server could send an excessively large response, causing Traefik to consume all available memory. This leads to an out-of-memory (OOM) condition, crashing the Traefik process and resulting in a denial of service for all routes it manages.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-03-05 19:01:39 UTC
|