๐Ÿ” CVE Alert

CVE-2026-85597

UNKNOWN 0.0

Traefik before v2.11.55 mTLS Bypass via TLS Option Conflict

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Traefik before v2.11.55 contains a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client-certificate authentication by creating conflicting TLS options on multi-host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts.

CWE CWE-863
Vendor traefik
Product traefik
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for traefik traefik

Be the first to know when new unknown vulnerabilities affecting traefik traefik are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

traefik / traefik
0 < 2.11.55
traefik / traefik
3.0.0 โ‰ค 3.7.12

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/traefik/traefik/security/advisories/GHSA-g55h-rg46-x9c5 vulncheck.com: https://www.vulncheck.com/advisories/traefik-before-2.11.55-mtls-bypass-via-tls-option-conflict

Credits

๐Ÿ” james-yusuke