THREAT OPS › Threat News › [GHSA] GHSA-7ghq-v6jf-g56c (medium) — Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
[GHSA] GHSA-7ghq-v6jf-g56c (medium) — Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
GHSA-7ghq-v6jf-g56c Severity: medium CVE: CVE-2026-88012
Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unbounded
## Summary
There is a medium severity vulnerability in Traefik's HTTP/3 entry points: the `respondingTimeouts` settings were not applied to the HTTP/3 request path. `readTimeout` in particular is on by default at 60s and is documented as
MITRE ATT&CK techniques
- Cloud ServicesT1021.007
Indicators of compromise
- 01811bb12d44f17280550f425f5e3128d6c325f2665c09e67a651ca535f490cesha256
- CVE-2026-88012cve
- http://127.0.0.1:8080url
- 6.6.114.1ipv4
Original source: https://github.com/advisories/GHSA-7ghq-v6jf-g56c