CVE-2026-25949Disclosure(traefik / traefik)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch traefik traefik systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated client can bypass Traefik entrypoint respondingTimeouts.readTimeout by sending the 8-byte Postgres SSLRequest (STARTTLS) prelude and then stalling, causing connections to remain open indefinitely, leading to a denial of service. This vulnerability is fixed in 3.6.8.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-400CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traefik

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 4 mentions (2026-02-12); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
traefik

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-02-12: 4Mentions · 2026-02-13: 1Patch / Workaround · 2026-02-12: 2Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-12: 402-1202-13
Signal classification2 categories
Disclosure
360.0%
Patch
240.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-124
Disclosure3Patch1
2026-02-131
Patch1
Full discourse5 posts
  • David Burgess@davidnburgess
    Patch

    Traefik v3.6.8 just dropped! Crucial security update fixing CVE-2026-25949 is LIVE. Plus, enjoy smoother ACME certs, stronger healthchecks, & better TLS stability. Upgrade now! More info: https://github.com/traefik/traefik/releases/tag/v3.6.8 #selfhosted #homelab https://t.co/BdiIU8NM1y

    Post summary

    The tweet announces the Traefik v3.6.8 release, highlighting that it includes a security patch for CVE-2026-25949 and urging users to upgrade.

    00030260
    2.2K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25949 Traefik is an HTTP reverse proxy and load balancer. Prior to 3.6.8, there is a potential vulnerability in Traefik managing STARTTLS requests. An unauthenticated clien… https://www.cve.org/CVERecord?id=CVE-2026-25949

    Post summary

    A potential STARTTLS handling vulnerability in Traefik before version 3.6.8 has been disclosed; the issue is mitigated by upgrading to 3.6.8.

    00020256
    56.5K followersView on X
  • TRONCAL Yannick@ytroncal
    Disclosure

    CVE-2026-25949: Traefik's Eternal Wait: Bypassing TCP Timeouts with Postgres Magic Bytes https://dev.to/cverports/cve-2026-25949-traefiks-eternal-wait-bypassing-tcp-timeouts-with-postgres-magic-bytes-1cdo

    Post summary

    The headline announces CVE-2026-25949, a Traefik vulnerability that allows bypassing TCP timeouts via Postgres magic bytes, but no proof‑of‑concept, exploit, patch, or evidence of active exploitation is provided.

    0000057
    127 followersView on X
  • Volerion@VolerionSec
    Patch

    🚨 CVE-2026-25949: Traefik before 3.6.8 mishandles Postgres STARTTLS, letting anyone keep connections open indefinitely and knock your reverse proxy offline. Upgrade to 3.6.8 now! Full advisory ➡️ https://volerion.com/vulnerabilities/CVE-2026-25949 #Traefik #infosec #DevOps

    Post summary

    The tweet warns that Traefik versions before 3.6.8 mishandle Postgres STARTTLS, allowing attackers to keep connections open indefinitely and bring down the reverse proxy, and urges users to upgrade to version 3.6.8, with a full advisory link provided.

    0000056
    51 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25949: Traefik's Eternal Wait: Bypassing TCP Timeouts with Postgres Magic Bytes Traefik, the ubiquitous cloud-native edge router, has a nasty habit of trusting Postgres connections too early. CVE-2026-25949 allows an unauthenticated attacker ... https://cvereports.com/reports/CVE-2026-25949

    Post summary

    The passage announces CVE‑2026‑25949, describing how Traefik improperly trusts early Postgres connections and allows unauthenticated attackers to bypass TCP timeouts, but it offers no PoC, exploit code, or patch details.

    0000054
    27 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apptraefiktraefik---

Explore more