# New Security Updates for Traefik 2.10 and 3.0.0-beta

**URL:** <https://community.traefik.io/t/new-security-updates-for-traefik-2-10-and-3-0-0-beta/20145>\
**Category:** Traefik v2\
**Created:** [October 13, 2023, 8:10am UTC](https://community.traefik.io/t/new-security-updates-for-traefik-2-10-and-3-0-0-beta/20145 "2023-10-13T08:10:31Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nicomengin](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/nicomengin/32/5507_2.png) [@nicomengin](https://community.traefik.io/u/nicomengin)\
**Post date:** [October 13, 2023, 8:10am UTC](https://community.traefik.io/t/new-security-updates-for-traefik-2-10-and-3-0-0-beta/20145/1 "2023-10-13T08:10:31Z")

</div>

On October 6, 2023, Go published [CVE-2023-39325](https://github.com/golang/go/issues/63417) to solve the issue described in [CVE-2023-44487](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487). These describe a vulnerability in Go managing HTTP/2 requests, which impacts Traefik.

This vulnerability could be exploited to cause a denial of service.

As of October 12, 2023, We have patched this vulnerability with [Traefik Proxy 2.10.5](https://github.com/traefik/traefik/releases/tag/v2.10.5) and [Traefik Proxy 3.0.0-beta4](https://github.com/traefik/traefik/releases/tag/v3.0.0-beta4).

You can find more information in the [Github Advisory](https://github.com/traefik/traefik/security/advisories/GHSA-7v4p-328v-8v5g) we’ve published.

If you have any questions or comments about this advisory, please add a comment.

---

<div class="post-metadata">

**Author:** ![ade-owasp-sf](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/ade-owasp-sf/32/7718_2.png) [@ade-owasp-sf](https://community.traefik.io/u/ade-owasp-sf)\
**Post date:** [October 17, 2023, 3:33pm UTC](https://community.traefik.io/t/new-security-updates-for-traefik-2-10-and-3-0-0-beta/20145/2 "2023-10-17T15:33:49Z")

</div>

Hi, it looks like now, or before, there is CVE-2023-28840 affecting the updated image. Any plan to fix for CVE-2023-28840 soon? In the meantime, any advice on how to manually patch for this issue? Thanks.

---

<div class="post-metadata">

**Author:** ![svx](https://sea2.discourse-cdn.com/flex020/user_avatar/community.traefik.io/svx/32/6429_2.png) [@svx](https://community.traefik.io/u/svx)\
**Post date:** [October 19, 2023, 1:32pm UTC](https://community.traefik.io/t/new-security-updates-for-traefik-2-10-and-3-0-0-beta/20145/3 "2023-10-19T13:32:02Z")

</div>

Hi @ade-owasp-sf, thanks for your interest in Traefik!

Please be sure that we analyze all CVEs related to Traefik and guarantee their treatment in the shortest possible time **when** we are impacted by them.

Traefik is not impacted by this CVE.  
Traefik uses a small part of the API client, the CVE is not about something used in Traefik.

Potential false positives related to vulnerability scanning tools are a known issue.
