Impact
Traefik releases before v2.11.55 and v3.0.0 through v3.7.10 contain a TLS option conflict resolution vulnerability that allows unauthenticated attackers to bypass client‑certificate authentication by creating conflicting TLS options on multi‑host routers. Attackers can reach protected backends by exploiting shared TLS resolution across multiple hostnames in a single router rule, causing the strict mTLS requirement to fall back to default options for all hosts. This configuration flaw is a permission management failure identified as CWE‑303 and CWE‑863, compromising confidentiality and integrity by permitting unauthorized data access.
Affected Systems
All Traefik releases prior to v2.11.55 and all releases v3.0.0 through v3.7.10 that use multi‑host routers with shared TLS resolution and enforce strict mTLS on some hostnames are vulnerable. The affected product is the Traefik reverse‑proxy router, which is deployed in a wide range of micro‑service and web‑application environments.
Risk and Exploitability
The base CVSS score of 8.2 indicates high severity. The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting currently low evidence of widespread exploitation. The attack can be carried out remotely by an unauthenticated adversary with network access to the Traefik instance and the ability to craft TLS options in a request. No privileged credentials or exploitation of code execution are required.
OpenCVE Enrichment