CVE-2026-85597

Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*

History

16 Sep 2026, 20:42

Type Values Removed Values Added
CPE cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:*
First Time Traefik
Traefik traefik
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
References () https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 - () https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 - Exploit, Mitigation, Patch, Vendor Advisory
References () https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict - () https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict - Third Party Advisory

Information

Published : 2026-09-04 12:17

Updated : 2026-09-16 20:42


NVD link : CVE-2026-85597

Mitre link : CVE-2026-85597

CVE.ORG link : CVE-2026-85597


JSON object : View

Products Affected

traefik

  • traefik
CWE
CWE-863

Incorrect Authorization