CVE-2023-54365
Go 취약성 분석 및 완화

개요

CVE-2023-54365 is a denial-of-service vulnerability in Traefik's HTTP/2 request handling, inherited from the Go standard library's HTTP/2 implementation via the 'Rapid Reset' technique (related to CVE-2023-44487 and CVE-2023-39325). It affects Traefik versions prior to 2.10.5 and 3.0.0-beta1 through 3.0.0-beta3, as well as Go versions prior to 1.20.10 and 1.21.0–1.21.2. Red Hat OpenShift AI (RHOAI) is also listed as an affected product. The CVE was published on June 23, 2026, with a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.7 (High) (Github Advisory, Traefik Advisory, Red Hat Bugzilla).

기술적 세부 사항

The root cause is uncontrolled resource consumption (CWE-400) and allocation of resources without limits or throttling (CWE-770) in the Go standard library's golang.org/x/net HTTP/2 implementation. The vulnerability is not caused by Traefik-specific code; rather, Traefik inherited it by depending on a vulnerable version of Go's HTTP/2 module (Red Hat CSAF). An unauthenticated remote attacker exploits the 'Rapid Reset' technique by rapidly opening and immediately canceling HTTP/2 streams (via RST_STREAM frames), causing the server to allocate resources for each stream without adequate throttling, ultimately exhausting server capacity. No authentication or user interaction is required, and the attack can be automated at scale (Traefik Advisory, Github Advisory).

영향

Successful exploitation results in a denial of service, rendering the Traefik reverse proxy/load balancer unavailable to legitimate users. There is no impact on confidentiality or integrity — the attack is purely an availability concern. Because Traefik commonly serves as an ingress controller in containerized and cloud-native environments, its unavailability can cascade to all backend services it proxies, potentially causing broad service outages (Red Hat CSAF, Github Advisory).

착취 단계

  1. Reconnaissance: Identify internet-facing Traefik instances running versions prior to 2.10.5 (v2 branch) or 3.0.0-beta4 (v3 branch) using tools like Shodan, Censys, or by inspecting HTTP response headers (e.g., Server: Traefik).
  2. Establish HTTP/2 connection: Initiate a TLS connection to the target Traefik instance and negotiate HTTP/2 using ALPN (Application-Layer Protocol Negotiation).
  3. Rapid stream creation: Using an HTTP/2 client or custom tooling, rapidly open a large number of HTTP/2 streams (HEADERS frames) in quick succession without waiting for server responses.
  4. Immediate stream cancellation: For each opened stream, immediately send an RST_STREAM frame to cancel it, preventing the server from completing request processing while still consuming server-side resources.
  5. Resource exhaustion: Repeat steps 3–4 at high volume to exhaust the server's goroutine pool, memory, or CPU, causing Traefik to become unresponsive to legitimate traffic (Traefik Advisory, Github Advisory).

타협의 징후

  • Network: Sudden spike in HTTP/2 connections from one or a small number of source IPs; high volume of RST_STREAM frames observed in network captures on port 443 or 80; abnormally high rate of short-lived HTTP/2 streams.
  • Logs: Traefik access logs showing a flood of requests with immediate resets or errors (e.g., stream reset by peer, connection reset); unusually high request rates from specific clients with no corresponding successful responses.
  • Process/System: Elevated CPU and memory usage on the Traefik process; goroutine count growing unboundedly (visible via Traefik's /metrics or /debug/pprof endpoints if exposed); system-level resource exhaustion indicators such as OOM events.
  • Availability: Legitimate users experiencing timeouts or connection refused errors when accessing services proxied by Traefik during the attack window (Red Hat CSAF).

완화 및 해결 방법

The primary remediation is to upgrade Traefik to version 2.10.5 (v2 branch) or 3.0.0-beta4 (v3 branch), which include updated Go HTTP/2 dependencies containing the upstream fix. No configuration-based workaround is available from the Traefik project. As a supplementary defense-in-depth measure, consider implementing rate limiting and connection throttling at the network or load balancer level to reduce the impact of HTTP/2 stream exhaustion attacks. Red Hat OpenShift AI (RHOAI) users should apply available updates to the odh-rhel9-operator and rhai-cli-rhel9 components (Traefik Advisory, Red Hat CSAF).

추가 자료


근원이 보고서는 AI를 사용하여 생성되었습니다.

관련 Go 취약점:

CVE ID

심각도

점수

기술

구성 요소 이름

CISA KEV 익스플로잇

수정 사항이 있습니다.

게시된 날짜

CVE-2023-54365HIGH8.7
  • Go logoGo
  • kubeflow-katib
아니요Jun 23, 2026
CVE-2026-39822HIGH7.8
  • Go logoGo
  • victoriatraces-fips
아니요Jul 08, 2026
CVE-2026-42504HIGH7.5
  • Go logoGo
  • vault-k8s-fips
아니요Jun 02, 2026
CVE-2026-42505MEDIUM5.3
  • Go logoGo
  • kubescape-downloader-fips
아니요Jul 08, 2026
CVE-2026-42507MEDIUM5.3
  • Go logoGo
  • moby-ryuk
아니요Jun 02, 2026

무료 취약성 평가

클라우드 보안 태세를 벤치마킹합니다

9개의 보안 도메인에서 클라우드 보안 관행을 평가하여 위험 수준을 벤치마킹하고 방어의 허점을 식별합니다.

평가 요청

추가 Wiz 리소스

맞춤형 데모 받기

맞춤형 데모 신청하기

"내가 본 최고의 사용자 경험은 클라우드 워크로드에 대한 완전한 가시성을 제공합니다."
데이비드 에슬릭최고정보책임자(CISO)
"Wiz는 클라우드 환경에서 무슨 일이 일어나고 있는지 볼 수 있는 단일 창을 제공합니다."
아담 플레처최고 보안 책임자(CSO)
"우리는 Wiz가 무언가를 중요한 것으로 식별하면 실제로 중요하다는 것을 알고 있습니다."
그렉 포니아토프스키위협 및 취약성 관리 책임자