CVE-2023-47633

HIGH

Traefik < 2.10.6 and < 3.0.0-beta5 - Denial of Service via Docker Integration

Title source: llm
STIX 2.1

Description

Traefik is an open source HTTP reverse proxy and load balancer. The traefik docker container uses 100% CPU when it serves as its own backend, which is an automatically generated route resulting from the Docker integration in the default configuration. This issue has been addressed in versions 2.10.6 and 3.0.0-beta5. Users are advised to upgrade. There are no known workarounds for this vulnerability.

References (3)

Core 3
Core References
Exploit, Third Party Advisory x_refsource_confirm
https://github.com/traefik/traefik/security/advisories/GHSA-6fwg-jrfw-ff7p

Scores

CVSS v3 7.5
EPSS 0.0127
EPSS Percentile 66.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-400
Status published
Products (4)
traefik/traefik 3.0.0 beta1 (4 CPE variants)
traefik/traefik < 2.10.5
traefik/traefik 0 - 2.10.6Go
traefik/traefik 0 - 3.0.0-beta5Go
Published Dec 04, 2023
Tracked Since Feb 18, 2026