Bishop Fox published an advisory covering the vulnerability in Traefik affecting HTTP/3 that allows unauthenticated attackers to hold requests open indefinitely, consuming upstream connections.
Published
Signal category
Products & Services
Quote
“Our advisory covers: • Why HTTP/3 bypassed the timeout • How the issue impacts backend services • The versions affected • The fixes now available”
— Bishop Fox team
Company
Bishop Fox
Attack to Protect
- Industry
- Computer and Network Security
- Location
- Tempe, US
- Company size
- 387 employees
Bishop Fox is recognized as the leading authority in offensive security, providing solutions ranging from continuous penetration testing, red teaming, and attack surface management to product, cloud, and application security assessments. Enterprises have been told that breaches are inevitable. But we don’t accept that. We focus on offensive security because we believe securing modern organizations requires a "forward defense" approach that proactively uncovers and eliminates exposures before they are exploited. Over the past 20 years, we’ve worked with more than 25% of the Fortune 100, 8 of the top 10 global tech companies, and hundreds of other organizations to improve their security. Security isn’t just a job to us. We do this because we love it — and because we're committed to the common good. In fact, we have authored 20+ open-source tools, shared groundbreaking research, and published more than 50 security advisories in the last 5 years. Learn more about us at bishopfox.com or follow us on X @bishopfox for the latest updates.
Founded 2005