highVulnerability

GHSA-4hjq-9h5c-252j

## Summary More Details: - https://nvd.nist.gov/vuln/detail/CVE-2026-27141 - https://pkg.go.dev/golang.org/x/net/http2?tab=versions ## Patches - https://github.com/traefik/traefik/releases/tag/v3.6.10 - https://github.com/traefik/traefik/releases/tag/v2.11.40 ## For more information If you have any questions or comments about this advisory, please [open an issue](https://github.com/traefik/traefik/issues).

Properties

ghsa_id
GHSA-4hjq-9h5c-252j
severity
high
summary
Traefik: HTTP/2 frames can cause a running server to panic
cve_id
GHSA-4hjq-9h5c-252j
is_ghsa_only
true
ghsa_published
2026-03-12T14:48:02Z
source_url
https://github.com/advisories/GHSA-4hjq-9h5c-252j
ghsa_updated
2026-03-12T14:48:03Z

Related Entities (4)

AFFECTS (2)

[Software]go/github.com/traefik/traefik/v3
[Software]go/github.com/traefik/traefik/v2

HAS_WEAKNESS (1)

[Weakness]NULL Pointer Dereference

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph