Traefik before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.
References
| Link | Resource |
|---|---|
| https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 | Exploit Mitigation Patch Vendor Advisory |
| https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
16 Sep 2026, 20:42
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:traefik:traefik:*:*:*:*:*:*:*:* | |
| First Time |
Traefik
Traefik traefik |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.1 |
| References | () https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 - Exploit, Mitigation, Patch, Vendor Advisory | |
| References | () https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict - Third Party Advisory |
Information
Published : 2026-09-04 12:17
Updated : 2026-09-16 20:42
NVD link : CVE-2026-85597
Mitre link : CVE-2026-85597
CVE.ORG link : CVE-2026-85597
JSON object : View
Products Affected
traefik
- traefik
CWE
CWE-863
Incorrect Authorization
